CVE-2016-4537: Input Validation
Fixed bug (bcpowmod accepts negative scale and corrupts one definition). (CVE-2016-4537, CVE-2016-4538)
Other sources
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2016-4537.
What is the severity of CVE-2016-4537?
The severity of CVE-2016-4537 is critical with a CVSS score of 9.8.
What is the affected software?
The affected software includes PHP versions before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6.
How can remote attackers exploit CVE-2016-4537?
Remote attackers can exploit CVE-2016-4537 by using a crafted call to the bcpowmod function, which can cause a denial of service or other unspecified impact.
Is there a fix available for CVE-2016-4537?
Yes, the fix for CVE-2016-4537 is included in PHP version 5.5.35, 5.6.21, and 7.0.6.