CVE-2016-5094: Integer Overflow
Integer overflow in the phphtmlentities function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from the htmlspecialchars function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5094?
CVE-2016-5094 has a medium severity rating due to its potential to cause denial of service.
How do I fix CVE-2016-5094?
To fix CVE-2016-5094, update PHP to version 5.5.36 or higher, or 5.6.22 or higher.
Which versions of PHP are affected by CVE-2016-5094?
CVE-2016-5094 affects PHP versions prior to 5.5.36 and 5.6.x before 5.6.22.
What types of attacks can be executed using CVE-2016-5094?
CVE-2016-5094 can allow remote attackers to execute denial of service attacks by causing large output strings.
Is CVE-2016-5094 a common vulnerability?
CVE-2016-5094 is a known vulnerability that affects several older versions of PHP widely used in web applications.