Lucene search

K
f5F5F5:K42065024
HistoryJun 09, 2016 - 12:00 a.m.

K42065024 : PHP vulnerability CVE-2016-4070

2016-06-0900:00:00
my.f5.com
19

AI Score

7.4

Confidence

Low

EPSS

0.307

Percentile

97.0%

Security Advisory Description

DISPUTED Integer overflow in the php_raw_url_encode function in ext/standard/url.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to cause a denial of service (application crash) via a long string to the rawurlencode function. NOTE: the vendor says "Not sure if this qualifies as security issue (probably not). (CVE-2016-4070)
Impact
BIG-IP, BIG-IQ, and Enterprise Manager products marked with a severity of Low are not vulnerable in default configurations. However, if custom PHP files are created by leveraging the URL encode methods mentioned in the CVE description, systems may become vulnerable to denial-of-service (DoS) attacks.
BIG-IP products marked with a severity of Medium may be vulnerable when an authenticated administrative user inserts very large strings into configuration parameters. This is unlikely to be a valid configuration, and while the affected code is present on the BIG-IP system, we believe that general protections already in place on the system would prevent direct exposure to this vulnerability.