Lucene search

K
f5F5F5:K51390683
HistoryAug 03, 2016 - 12:00 a.m.

K51390683 : PHP vulnerabilities CVE-2016-5094 and CVE-2016-5095

2016-08-0300:00:00
my.f5.com
18

8.2 High

AI Score

Confidence

Low

0.049 Low

EPSS

Percentile

92.8%

Security Advisory Description

Integer overflow in the php_html_entities function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from the htmlspecialchars function.

Integer overflow in the php_escape_html_entities_ex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from a FILTER_SANITIZE_FULL_SPECIAL_CHARS filter_var call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-5094.
Impact
Although BIG-IP and BIG-IQ software contains the vulnerable code, BIG-IP and BIG-IQ systems do not use the vulnerable code in a way that exposes the vulnerability in a standard default configuration. When exploited, the PHP module may encounter an out-of-memory error that affects the Configuration utility.