First published: Sun Aug 07 2016(Updated: )
Fixed bug (integer overflow in ZipArchive::getFrom*). (CVE-2016-3078)
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PHP PHP | >=7.0.0<7.0.6 | |
PHP PHP | <7.0.6 | 7.0.6 |
debian/php7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this bug is CVE-2016-3078.
CVE-2016-3078 has a severity rating of 9.8 (critical).
The PHP versions before 7.0.6 are affected by CVE-2016-3078.
CVE-2016-3078 can be exploited by a crafted call to the getFromIndex or getFromName functions in the ZipArchive class.
To fix CVE-2016-3078, update your PHP installation to version 7.0.6 or later.