Vulnerability Name:

CVE-2016-7133 (CCN-116951)

Assigned:2016-08-18
Published:2016-08-18
Updated:2017-07-01
Summary:Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.
CVSS v3 Severity:8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-190
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2016-7133

Source: MLIST
Type: Mailing List
[oss-security] 20160902 Re: CVE assignment for PHP 5.6.25 and 7.0.10 - and libcurl

Source: CCN
Type: PHP Web site
Version 7.0.11

Source: CONFIRM
Type: Release Notes
http://www.php.net/ChangeLog-7.php

Source: BID
Type: UNKNOWN
92765

Source: CCN
Type: BID-92765
PHP 'fopen_wrappers.c' Integer Overflow Vulnerability

Source: CONFIRM
Type: Exploit, Issue Tracking
https://bugs.php.net/bug.php?id=72742

Source: XF
Type: UNKNOWN
php-cve20167133-dos(116951)

Source: CONFIRM
Type: Issue Tracking, Patch
https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911?w=1

Source: GENTOO
Type: UNKNOWN
GLSA-201611-22

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-7133

Vulnerable Configuration:Configuration 1:
  • cpe:/a:php:php:7.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.2:-:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.3:-:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.4:-:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.5:-:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.6:-:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.7:-:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.8:-:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.9:-:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:php:php:7.0.10:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7714
    P
    log4j12-1.2.17-4.9.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7736
    P
    perl-5.26.1-150300.17.11.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:20167133
    V
    CVE-2016-7133
    2022-09-02
    oval:org.opensuse.security:def:10439
    P
    Security update for SDL2 (Important) (in QA)
    2022-01-12
    oval:org.opensuse.security:def:9885
    P
    Security update for SDL2 (Important) (in QA)
    2022-01-12
    oval:org.opensuse.security:def:10710
    P
    Security update for the Linux Kernel (Important) (in QA)
    2022-01-07
    oval:org.opensuse.security:def:9635
    P
    Security update for xorg-x11-server (Important)
    2021-12-20
    oval:org.opensuse.security:def:7012
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP1) (Important)
    2021-12-14
    oval:org.opensuse.security:def:10372
    P
    Security update for aaa_base (Moderate)
    2021-12-03
    oval:org.opensuse.security:def:10176
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:6987
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP1) (Important)
    2021-11-17
    oval:org.opensuse.security:def:9613
    P
    Security update for tomcat (Important)
    2021-11-16
    oval:org.opensuse.security:def:10170
    P
    Security update for qemu (Important)
    2021-11-04
    oval:org.opensuse.security:def:9605
    P
    Security update for busybox (Important)
    2021-10-27
    oval:org.opensuse.security:def:38662
    P
    Security update for MozillaFirefox (Important)
    2021-10-01
    oval:org.opensuse.security:def:10154
    P
    Security update for ghostscript (Critical)
    2021-09-15
    oval:org.opensuse.security:def:10148
    P
    Security update for ffmpeg (Important)
    2021-09-02
    oval:org.opensuse.security:def:10140
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:13912
    P
    libipa_hbac0-1.13.4-18.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14002
    P
    perl-32bit-5.18.2-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14249
    P
    libldap-2_4-2-2.4.41-18.29.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14068
    P
    xorg-x11-server-7.6_1.18.3-57.34 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14180
    P
    kernel-default-4.4.73-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14911
    P
    gstreamer-1.8.3-9.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13934
    P
    libnghttp2-14-1.7.1-1.84 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:9762
    P
    Security update for cpio (Important)
    2021-08-16
    oval:org.opensuse.security:def:14050
    P
    unzip-6.00-32.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14260
    P
    libmysqlclient18-10.0.30-28.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14087
    P
    apache2-mod_perl-2.0.8-11.43 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14205
    P
    libXvMC1-1.0.8-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14273
    P
    libpng12-0-1.2.50-19.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13904
    P
    libgraphite2-3-1.3.1-6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14933
    P
    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:11099
    P
    Security update for fossil (Moderate)
    2021-07-17
    oval:org.opensuse.security:def:10685
    P
    Security update for the Linux Kernel (Important)
    2021-07-15
    oval:org.opensuse.security:def:9743
    P
    Security update for ovmf (Important)
    2021-06-25
    oval:org.opensuse.security:def:10112
    P
    Security update for ovmf (Important)
    2021-06-25
    oval:org.opensuse.security:def:6912
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (Important)
    2021-06-18
    oval:org.opensuse.security:def:9728
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:10278
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:17064
    P
    libgadu3-1.11.4-1.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11412
    P
    libvorbis0-1.3.3-8.23 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17155
    P
    bash-lang-4.3-82.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16671
    P
    xorg-x11-devel-7.6-45.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16099
    P
    php7-devel-7.0.7-15.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17121
    P
    libid3tag0-0.15.1b-182.58 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17032
    P
    pidgin-otr-4.0.0-6.18 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36544
    P
    python-32bit-2.6.9-0.35.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16349
    P
    php7-devel-7.0.7-49.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11434
    P
    pcsc-ccid-1.4.14-1.45 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:124641
    P
    php7-devel-7.0.7-50.52.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17133
    P
    libsilc-1_1-2-1.1.10-24.128 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16635
    P
    php7-devel-7.0.7-50.52.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36502
    P
    libwebkit-1_0-2-1.2.7-0.17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:10087
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:10263
    P
    Security update for ceph (Important)
    2021-06-02
    oval:org.opensuse.security:def:6893
    P
    Security update for the Linux Kernel (Important)
    2021-05-18
    oval:org.opensuse.security:def:7076
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP2) (Important)
    2021-04-28
    oval:org.opensuse.security:def:6878
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP1) (Important)
    2021-04-07
    oval:org.opensuse.security:def:7063
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP2) (Important)
    2021-04-07
    oval:org.opensuse.security:def:9681
    P
    Security update for MozillaFirefox (Important)
    2021-04-01
    oval:org.opensuse.security:def:9863
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:9862
    P
    Security update for openssl-1_1 (Moderate)
    2021-03-09
    oval:org.opensuse.security:def:10216
    P
    Security update for wpa_supplicant (Important)
    2021-03-08
    oval:org.opensuse.security:def:9855
    P
    Security update for bind (Important)
    2021-03-02
    oval:org.opensuse.security:def:10397
    P
    Security update for salt (Critical)
    2021-02-26
    oval:org.opensuse.security:def:9837
    P
    Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork (Important)
    2021-02-11
    oval:org.opensuse.security:def:10163
    P
    Security update for python-urllib3 (Moderate)
    2021-02-08
    oval:org.opensuse.security:def:10297
    P
    Security update for go1.14 (Moderate)
    2021-01-26
    oval:org.opensuse.security:def:11121
    P
    Security update for viewvc (Moderate)
    2021-01-19
    oval:org.opensuse.security:def:35237
    P
    Security update for gimp (Moderate)
    2020-12-29
    oval:org.opensuse.security:def:10586
    P
    Security update for PackageKit (Moderate)
    2020-12-16
    oval:org.opensuse.security:def:7054
    P
    Security update for the Linux Kernel (Live Patch 6 for SLE 15 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:13245
    P
    apache2-mod_php7-7.0.7-15.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35753
    P
    libmusicbrainz4-2.1.5-5.18 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35820
    P
    ruby-1.8.7.p357-0.7.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16948
    P
    php7-devel-7.0.7-50.85.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16679
    P
    LibVNCServer-devel-0.9.9-17.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35704
    P
    g3utils-1.1.36-26.31 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16798
    P
    libbz2-devel-1.0.6-30.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16886
    P
    libsilc-1_1-2-1.1.10-24.115 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35864
    P
    apache2-mod_jk-1.2.26-1.30.110 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:46365
    P
    apache2-mod_php7-7.0.7-15.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35792
    P
    openslp-1.2.0-172.22.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35645
    P
    unrar-3.80.2-2.8 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16713
    P
    dovecot22-devel-2.2.31-19.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16855
    P
    libofx-0.9.9-3.7.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16922
    P
    libzmq3-4.0.4-15.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35006
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38554
    P
    bind on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9926
    P
    libtcnative-1-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10448
    P
    gnome-shell-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35101
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:10836
    P
    php7-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6785
    P
    libyaml-0-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35338
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:9931
    P
    libusbmuxd4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35485
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17819
    P
    Security update for php7 (Important)
    2020-12-01
    oval:org.opensuse.security:def:10483
    P
    libapr1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39411
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:9993
    P
    squidGuard on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10564
    P
    libxerces-c-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37912
    P
    liblouis-data on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10576
    P
    nut-cgi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10761
    P
    libmusicbrainz-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38007
    P
    mutt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10610
    P
    xfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38246
    P
    libSoundTouch0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35005
    P
    Security update for gnutls
    2020-12-01
    oval:org.opensuse.security:def:38729
    P
    libsrtp1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6755
    P
    libsmi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38394
    P
    libvncclient0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9913
    P
    libraptor2-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35017
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:38613
    P
    grub2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10814
    P
    libxslt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6763
    P
    libssh2-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10774
    P
    libplist++-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10453
    P
    hplip-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6831
    P
    rhythmbox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35395
    P
    Security update for openslp (Important)
    2020-12-01
    oval:org.opensuse.security:def:17793
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:10461
    P
    lib3ds-1-3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38773
    P
    perl-LWP-Protocol-https on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37911
    P
    libldb1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9978
    P
    python-requests on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10529
    P
    libpcscspy0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39453
    P
    Security update for php7 (Important)
    2020-12-01
    oval:org.opensuse.security:def:10012
    P
    w3m on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10752
    P
    libjson-c-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37923
    P
    libncurses5-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10591
    P
    python3-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7045
    P
    libgssglue1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38144
    P
    bzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38701
    P
    libmusicbrainz4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38304
    P
    libipa_hbac0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9904
    P
    libpng16-16 on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.xenial:def:201671330000000
    V
    CVE-2016-7133 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-09-12
    oval:com.ubuntu.precise:def:20167133000
    V
    CVE-2016-7133 on Ubuntu 12.04 LTS (precise) - medium.
    2016-09-11
    oval:com.ubuntu.trusty:def:20167133000
    V
    CVE-2016-7133 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-09-11
    oval:com.ubuntu.xenial:def:20167133000
    V
    CVE-2016-7133 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-09-11
    BACK
    php php 7.0.0
    php php 7.0.1
    php php 7.0.2
    php php 7.0.3
    php php 7.0.4
    php php 7.0.5
    php php 7.0.6
    php php 7.0.7
    php php 7.0.8
    php php 7.0.9
    php php 7.0.10