CVE-2016-5095: Integer Overflow
Integer overflow in the phpescapehtmlentitiesex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from a FILTERSANITIZEFULLSPECIALCHARS filtervar call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-5094.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5095?
CVE-2016-5095 has a severity rating that could lead to denial of service as a result of an integer overflow in PHP.
How do I fix CVE-2016-5095?
To resolve CVE-2016-5095, upgrade to PHP versions 5.5.36 or later, or to PHP 5.6.22 or later.
What versions of PHP are affected by CVE-2016-5095?
CVE-2016-5095 affects PHP versions prior to 5.5.36 and versions of 5.6.x before 5.6.22.
What type of exploitation is possible with CVE-2016-5095?
CVE-2016-5095 can be exploited by remote attackers to cause a denial of service.
Is there a patch available for CVE-2016-5095?
Yes, the patch for CVE-2016-5095 is included in newer releases of PHP after the vulnerable versions.