First published: Wed Jul 20 2016(Updated: )
The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PHP PHP | <=5.5.37 | |
PHP PHP | >=5.6.0<5.6.24 | |
PHP PHP | >=7.0.0<7.0.9 | |
<7.0.9 | 7.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.