CVE-2016-4540: Critical severity php vulnerability
Fixed bug (Out-of-bounds reads in zifgraphemestripos with negative offset). (CVE-2016-4540, CVE-2016-4541)
Other sources
The graphemestripos function in ext/intl/grapheme/graphemestring.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a negative offset.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2016-4540?
CVE-2016-4540 is a vulnerability in PHP that allows remote attackers to cause a denial of service or have other unspecified impact.
What is the severity of CVE-2016-4540?
CVE-2016-4540 has a severity rating of 9.8 (critical).
How does CVE-2016-4540 affect PHP?
CVE-2016-4540 affects PHP versions before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6.
How can CVE-2016-4540 be exploited?
CVE-2016-4540 can be exploited by remote attackers through the grapheme_stripos function in PHP.
Is there a fix for CVE-2016-4540?
Yes, CVE-2016-4540 is fixed in PHP version 7.0.6 and later.