CVE-2016-4541: Critical severity php vulnerability
Fixed bug (Out-of-bounds reads in zifgraphemestripos with negative offset). (CVE-2016-4540, CVE-2016-4541)
Other sources
The graphemestrpos function in ext/intl/grapheme/graphemestring.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a negative offset.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2016-4541?
CVE-2016-4541 is a vulnerability in PHP versions before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 that allows remote attackers to cause a denial of service or possibly have other unspecified impacts through a negative offset in the grapheme_strpos function.
How severe is CVE-2016-4541?
CVE-2016-4541 has a severity rating of 9.8 (critical).
How can CVE-2016-4541 be exploited?
CVE-2016-4541 can be exploited by remote attackers using a negative offset in the grapheme_strpos function to cause a denial of service or potentially have other impacts.
Which versions of PHP are affected by CVE-2016-4541?
Versions of PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 are affected by CVE-2016-4541.
Is there a fix for CVE-2016-4541?
Yes, the vulnerability has been fixed in PHP version 7.0.6.