Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
{ "vanir_signatures": [ { "deprecated": false, "target": { "function": "php_wddx_pop_element", "file": "ext/wddx/wddx.c" }, "source": "https://github.com/php/php-src/commit/e09845d32614a19188632f410316478fbb440ebd", "digest": { "function_hash": "256499925868157450184250045566717426855", "length": 3105.0 }, "id": "CVE-2016-4346-168acc40", "signature_version": "v1", "signature_type": "Function" }, { "deprecated": false, "target": { "function": "php_wddx_process_data", "file": "ext/wddx/wddx.c" }, "source": "https://github.com/php/php-src/commit/e09845d32614a19188632f410316478fbb440ebd", "digest": { "function_hash": "297808210448008143422161856745228178213", "length": 1454.0 }, "id": "CVE-2016-4346-63916535", "signature_version": "v1", "signature_type": "Function" }, { "deprecated": false, "target": { "file": "ext/wddx/wddx.c" }, "source": "https://github.com/php/php-src/commit/e09845d32614a19188632f410316478fbb440ebd", "digest": { "threshold": 0.9, "line_hashes": [ "240350071091354082169554641503322018360", "83239604679707749811593051196119658386", "227586690061435287287994965536507444467", "171971468238865359835315510260595594604", "34110307404906790365435565495275501781", "37364056837223290377158685987933560788", "158805433901848107125099228832282898903", "154096422045862655651765972076311404641" ] }, "id": "CVE-2016-4346-f1f44522", "signature_version": "v1", "signature_type": "Line" } ] }