← Back

CVE-2016-7134

nvd nist
Published: Sep 12, 2016Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.

Affected (10)

Products: Php: Php
1 product
Php
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Php
Version 7.0.0
Version 7.0.1
Version 7.0.2
Version 7.0.3
Version 7.0.4
Version 7.0.5
Version 7.0.6
Version 7.0.7
Version 7.0.8
Version 7.0.9

References (14)

Source: cve@mitre.org
Release Notes
Source: cve@mitre.org
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.