CVE-2016-6289: Buffer Overflow
Integer overflow in the virtualfileex function in TSRM/tsrmvirtualcwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.
Other sources
Fixed bug (Stack-based buffer overflow vulnerability in virtualfileex). (CVE-2016-6289)
— PHP
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6289?
CVE-2016-6289 has been rated as a moderate severity vulnerability due to potential denial of service issues.
How do I fix CVE-2016-6289?
To fix CVE-2016-6289, upgrade to PHP version 5.5.38, 5.6.24, or 7.0.9 or later.
What types of vulnerabilities are associated with CVE-2016-6289?
CVE-2016-6289 is associated with stack-based buffer overflow vulnerabilities caused by integer overflow.
Who is affected by CVE-2016-6289?
CVE-2016-6289 affects PHP versions before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9.
Can CVE-2016-6289 be exploited remotely?
Yes, CVE-2016-6289 can be exploited remotely, allowing attackers to cause denial of service.