CVE-2016-7134: Buffer Overflow
ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curlescape call.
Other sources
Fixed bug (Heap overflow in curlescape). (CVE-2016-7134)
— PHP
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7134?
CVE-2016-7134 has a severity rating that indicates it can lead to denial of service and potentially other impacts.
How do I fix CVE-2016-7134?
To fix CVE-2016-7134, upgrade PHP to version 7.0.10 or later.
What software versions are affected by CVE-2016-7134?
CVE-2016-7134 affects PHP versions from 7.0.0 to 7.0.9.
Can CVE-2016-7134 cause system breaches?
CVE-2016-7134 does not directly lead to system breaches but can cause denial of service due to memory allocation errors.
Is CVE-2016-7134 a critical vulnerability?
CVE-2016-7134 is considered a critical vulnerability as it can lead to significant application instability.