CVE-2016-4346
published 2016-05-22CVE-2016-4346: Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.67%
92.1th percentile
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| php | php | >= 7.0.0 < 7.0.4 | 7.0.4 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.16 | 5.5.9+dfsg-1ubuntu4.16 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g567-h7p8-q9q9: Integer overflow in the str_pad function in ext/standard/string
ghsa_unreviewed·2022-05-14
CVE-2016-4346 [CRITICAL] CWE-190 GHSA-g567-h7p8-q9q9: Integer overflow in the str_pad function in ext/standard/string
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
OSV
CVE-2016-4346: Integer overflow in the str_pad function in ext/standard/string
osv·2016-05-22·CVSS 9.8
CVE-2016-4346 [CRITICAL] CVE-2016-4346: Integer overflow in the str_pad function in ext/standard/string
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
Red Hat
php: Multiple heap overflows due to integer overflows
vendor_redhat·2016-02-20·CVSS 9.8
CVE-2016-4346 [CRITICAL] CWE-190 php: Multiple heap overflows due to integer overflows
php: Multiple heap overflows due to integer overflows
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 6) - Not affected
Package: php (Red Hat Enterprise Linux 7) - Not affected
Package: php54-php (Red Hat Software Collections) - Not affected
Package: php55-php (Red Hat Software Collections) - Not affected
Package: rh-php56-php (Red Hat Software Collections) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4344 CVE-2016-4345 CVE-2016-4346 php: Multiple heap overflows due to integer overflows
bugzilla·2016-03-07·CVSS 9.8
CVE-2016-4344 [CRITICAL] CVE-2016-4344 CVE-2016-4345 CVE-2016-4346 php: Multiple heap overflows due to integer overflows
CVE-2016-4344 CVE-2016-4345 CVE-2016-4346 php: Multiple heap overflows due to integer overflows
Multiple heap-based buffer overflow caused by integer overflows were found in xml_utf8_encode, zend_string_alloc and php_addcslashes functions.
Upstream bug:
https://bugs.php.net/bug.php?id=71637
Upstream patch:
http://git.php.net/?p=php-src.git;a=commit;h=57b997ebf99e0eb9a073e0dafd2ab100bd4a112d
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1315340]
---
CVE assignments via:
http://seclists.org/oss-sec/2016/q2/163
CVE-2016-4344 is for the issue in:
ext/xml/xml.c
CVE-2016-4345 is for the issue in:
ext/filter/sanitizing_filters.c
CVE-2016-4346 is for the issue in:
ext/standard/string.c
---
PHP 7 only. Additionally, these issue could only be trigg
Bugzilla
CVE-2016-4344 CVE-2016-4345 CVE-2016-4346 php: Multiple heap overflows due to integer overflows [fedora-all]
bugzilla·2016-03-07·CVSS 9.8
CVE-2016-4344 [CRITICAL] CVE-2016-4344 CVE-2016-4345 CVE-2016-4346 php: Multiple heap overflows due to integer overflows [fedora-all]
CVE-2016-4344 CVE-2016-4345 CVE-2016-4346 php: Multiple heap overflows due to integer overflows [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
http://lists.opensuse.org/opensuse-updates/2016-05/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2016-06/msg00027.htmlhttp://php.net/ChangeLog-7.phphttp://www.openwall.com/lists/oss-security/2016/04/28/2https://bugs.php.net/bug.php?id=71637http://lists.opensuse.org/opensuse-updates/2016-05/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2016-06/msg00027.htmlhttp://php.net/ChangeLog-7.phphttp://www.openwall.com/lists/oss-security/2016/04/28/2https://bugs.php.net/bug.php?id=71637
2016-05-22
Published