9.8
CVSSv3

CVE-2016-5769

Published: 07/08/2016 Updated: 28/11/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP prior to 5.5.37, 5.6.x prior to 5.6.23, and 7.x prior to 7.0.8 allow remote malicious users to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted length value, related to the (1) mcrypt_generic and (2) mdecrypt_generic functions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.6.0

php php 7.0.0

php php 7.0.7

php php 5.6.15

php php 5.6.16

php php 5.6.22

php php 5.6.3

php php

php php 7.0.1

php php 7.0.2

php php 5.6.1

php php 5.6.17

php php 5.6.18

php php 5.6.4

php php 5.6.5

php php 7.0.3

php php 7.0.4

php php 5.6.10

php php 5.6.11

php php 5.6.19

php php 5.6.2

php php 5.6.6

php php 5.6.7

php php 7.0.5

php php 7.0.6

php php 5.6.12

php php 5.6.13

php php 5.6.14

php php 5.6.20

php php 5.6.21

php php 5.6.8

php php 5.6.9

Vendor Advisories

Several security issues were fixed in PHP ...
Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development The vulnerabilities are addressed by upgrading PHP to the new upstream version 5623, which includes additional bug fixes Please refer to the upstream changelog for more information: phpnet/ChangeLog-5php#5623 ...
A stack consumption vulnerability in GD in PHP allows remote attackers to cause a denial of service via a crafted imagefilltoborder call (CVE-2015-8874) An integer overflow, leading to a heap-based buffer overflow was found in the imagecreatefromgd2() function of PHP's gd extension A remote attacker could use this flaw to crash a PHP application ...
Multiple integer overflows in mcryptc in the mcrypt extension in PHP before 5537, 56x before 5623, and 7x before 708 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted length value, related to the (1) mcrypt_generic and (2) mdecrypt ...