CVE-2016-5093: High severity php vulnerability
The geticuvalueinternal function in ext/intl/locale/localemethods.c in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7 does not ensure the presence of a '\0' character, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted localegetprimarylanguage call.
Other sources
Fixed bug (geticuvalueinternal out-of-bounds read). (CVE-2016-5093)
— PHP
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5093?
CVE-2016-5093 is rated as a moderate severity vulnerability, primarily due to its potential for denial of service.
How do I fix CVE-2016-5093?
To fix CVE-2016-5093, upgrade PHP to version 5.5.36, 5.6.22, or 7.0.7 or later.
What versions of PHP are affected by CVE-2016-5093?
CVE-2016-5093 affects PHP versions before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7.
What type of vulnerability is CVE-2016-5093?
CVE-2016-5093 is an out-of-bounds read vulnerability that may lead to denial of service.
Can CVE-2016-5093 be exploited remotely?
Yes, CVE-2016-5093 can be exploited remotely, allowing attackers to cause a denial of service.