CVE-2016-7134 Information
Description
ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://openwall.com/lists/oss-security/2016/09/02/9 [oss-security] 20160902 Re: CVE assignment for PHP 5.6.25 and 7.0.10
and libcurl http://www.php.net/ChangeLog-7.php http://www.securityfocus.com/bid/92766 http://www.securitytracker.com/id/1036680 https://bugs.php.net/bug.php?id=72674 https://github.com/php/php-src/commit/72dbb7f416160f490c4e9987040989a10ad431c7?w=1 https://security.gentoo.org/glsa/201611-22 ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: