CVE-2016-5770
published 2016-08-07CVE-2016-5770: Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.34%
93.7th percentile
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sierra | — | — |
| debian | debian_linux | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| php | php | < 5.5.37 | 5.5.37 |
| php | php | >= 5.6.0 < 5.6.23 | 5.6.23 |
| php | php | >= 7.0.0 < 7.0.8 | 7.0.8 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-5770: macOS Sierra 10.12
vendor_apple·2016-09-20·CVSS 9.8
CVE-2016-5770 [CRITICAL] CVE-2016-5770: macOS Sierra 10.12
Apple Security Update: About the security content of macOS Sierra 10.12
Product: macOS Sierra
Version: 10.12
CVE: CVE-2016-5770
Component: CVE-2016-5770
Red Hat
php: Int/size_t confusion in SplFileObject::fread
vendor_redhat·2016-06-23·CVSS 8.6
CVE-2016-5770 [HIGH] CWE-843 php: Int/size_t confusion in SplFileObject::fread
php: Int/size_t confusion in SplFileObject::fread
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.
A type confusion issue was found in the SPLFileObject fread() function. A remote attacker able to submit a specially crafted input to a PHP application, which uses this function, could use this flaw to execute arbitrary code with the privileges of the user running that PHP application.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 6) -
GHSA
GHSA-cc8q-wj33-74wc: Integer overflow in the SplFileObject::fread function in spl_directory
ghsa_unreviewed·2022-05-14·CVSS 8.6
CVE-2016-5770 [HIGH] CWE-190 GHSA-cc8q-wj33-74wc: Integer overflow in the SplFileObject::fread function in spl_directory
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5766 CVE-2016-5767 CVE-2016-5768 CVE-2016-5769 CVE-2016-5770 CVE-2016-5771 CVE-2016-5772 CVE-2016-5773 php: various flaws [fedora-all]
bugzilla·2016-06-29·CVSS 8.8
CVE-2016-5766 [HIGH] CVE-2016-5766 CVE-2016-5767 CVE-2016-5768 CVE-2016-5769 CVE-2016-5770 CVE-2016-5771 CVE-2016-5772 CVE-2016-5773 php: various flaws [fedora-all]
CVE-2016-5766 CVE-2016-5767 CVE-2016-5768 CVE-2016-5769 CVE-2016-5770 CVE-2016-5771 CVE-2016-5772 CVE-2016-5773 php: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2016-5770 php: Int/size_t confusion in SplFileObject::fread
bugzilla·2016-06-29·CVSS 9.8
CVE-2016-5770 [CRITICAL] CVE-2016-5770 php: Int/size_t confusion in SplFileObject::fread
CVE-2016-5770 php: Int/size_t confusion in SplFileObject::fread
An int/size_t confusion can happen in SplFileObject::fread
Upstream bug:
https://bugs.php.net/bug.php?id=72262
Upstream patch:
http://git.php.net/?p=php-src.git;a=commitdiff;h=7245bff300d3fa8bacbef7897ff080a6f1c23eba
CVE assignment:
http://seclists.org/oss-sec/2016/q2/589
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1351180]
---
php-5.6.23-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
php-5.6.23-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
---
php-5.6.23-1.fc23 has been pushed to the Fedora 23 stable repositor
http://github.com/php/php-src/commit/7245bff300d3fa8bacbef7897ff080a6f1c23eba?w=1http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2016-08/msg00003.htmlhttp://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.debian.org/security/2016/dsa-3618http://www.openwall.com/lists/oss-security/2016/06/23/4http://www.securityfocus.com/bid/91403https://bugs.php.net/bug.php?id=72262https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731https://support.apple.com/HT207170http://github.com/php/php-src/commit/7245bff300d3fa8bacbef7897ff080a6f1c23eba?w=1http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2016-08/msg00003.htmlhttp://php.net/ChangeLog-5.phphttp://rhn.redhat.com/errata/RHSA-2016-2750.htmlhttp://www.debian.org/security/2016/dsa-3618http://www.openwall.com/lists/oss-security/2016/06/23/4http://www.securityfocus.com/bid/91403https://bugs.php.net/bug.php?id=72262https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731https://support.apple.com/HT207170
2016-08-07
Published