The geticuvalueinternal function in ext/intl/locale/localemethods.c in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7 does not ensure the presence of a '\0' character, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted localegetprimary_language call.
{ "vanir_signatures": [ { "signature_version": "v1", "source": "https://github.com/php/php-src/commit/97eff7eb57fc2320c267a949cffd622c38712484", "deprecated": false, "signature_type": "Function", "target": { "file": "ext/intl/locale/locale_methods.c", "function": "get_icu_value_internal" }, "id": "CVE-2016-5093-02917de3", "digest": { "function_hash": "267995480029817361019472882597289164152", "length": 1745.0 } } ] }