Vulnerability Name: | CVE-2016-4345 (CCN-112805) | ||||||||||||||||||||
Assigned: | 2016-04-28 | ||||||||||||||||||||
Published: | 2016-04-28 | ||||||||||||||||||||
Updated: | 2022-07-20 | ||||||||||||||||||||
Summary: | Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow. | ||||||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-190 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-4345 Source: CONFIRM Type: Release Notes, Vendor Advisory http://php.net/ChangeLog-7.php Source: CCN Type: oss-sec Mailing List, Thu, 28 Apr 2016 11:57:38 -0400 (EDT) Re: [CVE Requests] PHP issues Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160428 [CVE Requests] PHP issues Source: CCN Type: PHP Web site Sec Bug #71637 Multiple Heap Overflow due to integer overflows | xml/filter_url/addcslashes Source: CONFIRM Type: Exploit, Issue Tracking, Patch, Vendor Advisory https://bugs.php.net/bug.php?id=71637 Source: XF Type: UNKNOWN php-cve20164345-bo(112805) Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-4345 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |