Integer overflow in PHP - #VU7684
Published: August 3, 2017
Vulnerability identifier: #VU7684
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code.
The weakness exists due to integer overflow in oci_bind_array_by_name. A remote attacker can trigger memory corruption, cause the system to crash or execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to integer overflow in oci_bind_array_by_name. A remote attacker can trigger memory corruption, cause the system to crash or execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
PHP
Remediation
Update to version 7.0.22.