CVE-2016-7418

Published on: 09/17/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:06 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Certain versions of Php from Php contain the following vulnerability:

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an incorrect boolean element in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.

  • CVE-2016-7418 has been assigned by [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.5 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE NONE HIGH

CVSS2 Score: 5 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE NONE PARTIAL

CVE References

Description Tags Link
Fix bug #73065: Out-Of-Bounds Read in php_wddx_push_element of wddx.c · php/[email protected] · GitHub Issue Tracking
Patch
github.com
text/html
URL Logo CONFIRM github.com/php/php-src/commit/c4cca4c20e75359c9a13a1f9a36cb7b4e9601d29?w=1
PHP Multiple Memory Corruption Errors Let Remote and Local Users Execute Arbitrary Code on the Target System - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1036836
[R6] SecurityCenter 5.4.1 Fixes Multiple Vulnerabilities - Security Advisory | Tenable Network Security www.tenable.com
text/html
URL Logo CONFIRM www.tenable.com/security/tns-2016-19
Red Hat Customer Portal access.redhat.com
text/html
URL Logo REDHAT RHSA-2018:1296
oss-security - Re: CVE assignment for PHP 5.6.26 and 7.0.11 Mailing List
www.openwall.com
text/html
URL Logo MLIST [oss-security] 20160915 Re: CVE assignment for PHP 5.6.26 and 7.0.11
PHP: PHP 7 ChangeLog Release Notes
www.php.net
text/html
URL Logo CONFIRM www.php.net/ChangeLog-7.php
PHP CVE-2016-7418 Out-of-Bounds Read Denial of Service Vulnerability cve.report (archive)
text/html
URL Logo BID 93011
PHP: PHP 5 ChangeLog Release Notes
www.php.net
text/html
URL Logo CONFIRM www.php.net/ChangeLog-5.php
PHP :: Sec Bug #73065 :: Out-Of-Bounds Read in php_wddx_push_element of wddx.c Exploit
Issue Tracking
bugs.php.net
text/html
URL Logo CONFIRM bugs.php.net/bug.php?id=73065
PHP: Multiple vulnerabilities (GLSA 201611-22) — Gentoo security security.gentoo.org
text/html
URL Logo GENTOO GLSA-201611-22

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationPhpPhp7.0.0AllAllAll
ApplicationPhpPhp7.0.1AllAllAll
ApplicationPhpPhp7.0.10AllAllAll
ApplicationPhpPhp7.0.2AllAllAll
ApplicationPhpPhp7.0.3AllAllAll
ApplicationPhpPhp7.0.4AllAllAll
ApplicationPhpPhp7.0.5AllAllAll
ApplicationPhpPhp7.0.6AllAllAll
ApplicationPhpPhp7.0.7AllAllAll
ApplicationPhpPhp7.0.8AllAllAll
ApplicationPhpPhp7.0.9AllAllAll
ApplicationPhpPhp7.0.0AllAllAll
ApplicationPhpPhp7.0.1AllAllAll
ApplicationPhpPhp7.0.10AllAllAll
ApplicationPhpPhp7.0.2AllAllAll
ApplicationPhpPhp7.0.3AllAllAll
ApplicationPhpPhp7.0.4AllAllAll
ApplicationPhpPhp7.0.5AllAllAll
ApplicationPhpPhp7.0.6AllAllAll
ApplicationPhpPhp7.0.7AllAllAll
ApplicationPhpPhp7.0.8AllAllAll
ApplicationPhpPhp7.0.9AllAllAll
ApplicationPhpPhpAllAllAllAll
  • cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*: