Lucene search

K
f5F5F5:K64412100
HistoryAug 29, 2016 - 12:00 a.m.

K64412100 : PHP vulnerability CVE-2016-4073

2016-08-2900:00:00
my.f5.com
28

AI Score

8.2

Confidence

Low

EPSS

0.047

Percentile

92.8%

Security Advisory Description

Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted mb_strcut call. (CVE-2016-4073)

Impact

An attacker may access unauthorized information, run arbitrary code, or cause a disruption of service. In default configurations, the BIG-IP system is not vulnerable; however, the vulnerability can be exposed through custom PHP scripts.