The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-5399.json"
[
{
"signature_version": "v1",
"id": "CVE-2016-5399-3da0fc9f",
"source": "https://github.com/php/php-src/commit/c86338a35cda8514c8d2f38e62808f9bcfe0e4cb",
"digest": {
"threshold": 0.9,
"line_hashes": [
"198011536025072107975883186380452148843",
"331728417024842654446570071457159069395",
"205456331668105326830182380336029223146",
"164282985402725457749299583506046134408",
"320137256578601229186691392718001358014"
]
},
"target": {
"file": "ext/standard/basic_functions.c"
},
"signature_type": "Line",
"deprecated": false
}
]