CVE-2016-5095

HIGH

Description

Integer overflow in the php_escape_html_entities_ex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from a FILTER_SANITIZE_FULL_SPECIAL_CHARS filter_var call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-5094.

References

http://php.net/ChangeLog-5.php

http://www.debian.org/security/2016/dsa-3602

http://www.openwall.com/lists/oss-security/2016/05/26/3

http://www.securityfocus.com/bid/92144

https://bugs.php.net/bug.php?id=72135

https://gist.github.com/8ef775c117d84ff15185953990a28576

Details

Source: MITRE

Published: 2016-08-07

Updated: 2016-11-28

Type: CWE-190

Risk Information

CVSS v2.0

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3.0

Base Score: 8.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Impact Score: 4.7

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (13 total)

IDNameProductFamilySeverity
93161SUSE SLES11 Security Update : php53 (SUSE-SU-2016:1638-1) (BACKRONYM)NessusSuSE Local Security Checks
critical
93160SUSE SLED12 / SLES12 Security Update : php5 (SUSE-SU-2016:1633-1)NessusSuSE Local Security Checks
high
92708F5 Networks BIG-IP : PHP vulnerabilities (K51390683)NessusF5 Networks Local Security Checks
high
92699Ubuntu 12.04 LTS / 14.04 LTS / 16.04 LTS : php5, php7.0 vulnerabilities (USN-3045-1) (httpoxy)NessusUbuntu Local Security Checks
high
92104Fedora 22 : php (2016-65f1ffdc0c)NessusFedora Local Security Checks
high
9393PHP 5.5.x < 5.5.37 / 5.6.x < 5.6.23 / 7.0.x < 7.0.8 Multiple VulnerabilitiesNessus Network MonitorWeb Servers
high
91900Debian DLA-533-1 : php5 security updateNessusDebian Local Security Checks
high
91869openSUSE Security Update : php5 (openSUSE-2016-776)NessusSuSE Local Security Checks
high
91665SUSE SLES11 Security Update : php53 (SUSE-SU-2016:1581-1)NessusSuSE Local Security Checks
critical
91615Debian DSA-3602-1 : php5 - security updateNessusDebian Local Security Checks
high
91585openSUSE Security Update : php5 (openSUSE-2016-703)NessusSuSE Local Security Checks
high
91466Amazon Linux AMI : php55 (ALAS-2016-707)NessusAmazon Linux Local Security Checks
high
91465Amazon Linux AMI : php56 (ALAS-2016-706)NessusAmazon Linux Local Security Checks
high