Zend/zendalloc.c in PHP 7.x before 7.0.10, when openbasedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.
{ "vanir_signatures": [ { "deprecated": false, "source": "https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911", "target": { "function": "zend_mm_realloc_heap", "file": "Zend/zend_alloc.c" }, "digest": { "function_hash": "38175289135737973986616221052495021956", "length": 5848.0 }, "id": "CVE-2016-7133-44c094ca", "signature_version": "v1", "signature_type": "Function" }, { "deprecated": false, "source": "https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911", "target": { "file": "Zend/zend_alloc.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "111961339304292541928537430669186257034", "210124735288199671747588466160865165662", "205982916566899775144936522917698108524", "110388679627889035768047294777568249569", "3170154757877869724997979614184162861", "63456613087521314659647146272467556526", "1906302105730951111839831544056783248", "102314375066585841612098046167144926817", "257177565617055216047557024224075629103", "127954140771692017760430304661574497539", "164390002335094048823598899959093131430", "259951822483819625095797803158310720835", "266711533443493267362270896471606063165", "254621335695541198791336833240291131338", "319646960869429078803581925529288413616", "296482086816160290772405381502417265830", "67887943793448817886930941070115941163" ] }, "id": "CVE-2016-7133-b6ee4d35", "signature_version": "v1", "signature_type": "Line" } ] }