CVE-2016-4346: Integer Overflow
Integer overflow in the strpad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
Other sources
Fixed bug (Multiple Heap Overflow due to integer overflows in xml/filterurl/addcslashes). (CVE-2016-4344, CVE-2016-4345, CVE-2016-4346)
— PHP
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4346?
CVE-2016-4346 has a high severity level due to its potential for causing denial of service attacks and heap-based buffer overflows.
How do I fix CVE-2016-4346?
To fix CVE-2016-4346, upgrade PHP to version 7.0.4 or later.
What systems are affected by CVE-2016-4346?
CVE-2016-4346 affects PHP versions prior to 7.0.4 and specific versions of openSUSE.
What kind of vulnerability is CVE-2016-4346?
CVE-2016-4346 is an integer overflow vulnerability that can lead to heap-based buffer overflows.
Can CVE-2016-4346 be exploited remotely?
Yes, CVE-2016-4346 can be exploited remotely, allowing attackers to impact the affected systems.