Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

PHP 7.0.x < 7.0.4 Multiple Vulnerabilities

Critical

Synopsis

The specific version of PHP that the system is running is reportedly affected by multiple vulnerabilities.

Description

The specific version of PHP that the system is running is reportedly affected by the following vulnerabilities:

- PHP contains an integer overflow condition in the php_filter_encode_url() function in ext/filter/sanitizing_filters.c. The issue is triggered as user-supplied input is not properly validated. This may allow a remote attacker to cause a heap-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code. (CVE-2016-4345)

- PHP contains an integer overflow condition in ext/standard/string.c. The issue is triggered as user-supplied input is not properly validated. This may allow a remote attacker to cause a heap-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code. (CVE-2016-4346)

Solution

Upgrade to PHP version 7.0.4 or later.