Lucene search

K
f5F5F5:K81081046
HistoryMay 23, 2016 - 12:00 a.m.

K81081046 : PHP vulnerabilities CVE-2016-4537 and CVE-2016-4538

2016-05-2300:00:00
my.f5.com
12

8 High

AI Score

Confidence

Low

0.036 Low

EPSS

Percentile

91.7%

Security Advisory Description

The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.

The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the zero, one, or two global variable, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.
Impact
There is no impact; F5 products are not affected by this vulnerability.