CVE-2016-7133

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-7133
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7133.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-7133
Downstream
Related
Published
2016-09-12T01:59:11Z
Modified
2025-10-15T08:24:32.843457Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Zend/zendalloc.c in PHP 7.x before 7.0.10, when openbasedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.

References

Affected packages

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

NEWS
NEWS-cvs2svn
POST_64BIT_BRANCH_MERGE
POST_AST_MERGE
POST_NATIVE_TLS_MERGE
POST_PHP7_EREG_MYSQL_REMOVALS
POST_PHP7_NSAPI_REMOVAL
POST_PHP7_REMOVALS
POST_PHPNG_MERGE
PRE_64BIT_BRANCH_MERGE
PRE_AST_MERGE
PRE_NATIVE_TLS_MERGE
PRE_PHP7_EREG_MYSQL_REMOVALS
PRE_PHP7_NSAPI_REMOVAL
PRE_PHP7_REMOVALS
PRE_PHPNG_MERGE

php-5.*

php-5.3.23RC1
php-5.3.29
php-5.3.29RC1
php-5.4.30RC1
php-5.4.32RC1
php-5.4.4RC2
php-5.5.24RC1
php-5.6.18RC1
php-5.6.19RC1
php-5.6.22RC1
php-5.6.23RC1
php-5.6.24RC1

php-7.*

php-7.0.3RC1
php-7.0.4RC1
php-7.0.5RC1
php-7.0.7RC1
php-7.0.8RC1
php-7.0.9RC1

Database specific

vanir_signatures

[
    {
        "signature_version": "v1",
        "target": {
            "function": "zend_mm_realloc_heap",
            "file": "Zend/zend_alloc.c"
        },
        "source": "https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911",
        "digest": {
            "length": 5848.0,
            "function_hash": "38175289135737973986616221052495021956"
        },
        "deprecated": false,
        "id": "CVE-2016-7133-44c094ca",
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "Zend/zend_alloc.c"
        },
        "source": "https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "111961339304292541928537430669186257034",
                "210124735288199671747588466160865165662",
                "205982916566899775144936522917698108524",
                "110388679627889035768047294777568249569",
                "3170154757877869724997979614184162861",
                "63456613087521314659647146272467556526",
                "1906302105730951111839831544056783248",
                "102314375066585841612098046167144926817",
                "257177565617055216047557024224075629103",
                "127954140771692017760430304661574497539",
                "164390002335094048823598899959093131430",
                "259951822483819625095797803158310720835",
                "266711533443493267362270896471606063165",
                "254621335695541198791336833240291131338",
                "319646960869429078803581925529288413616",
                "296482086816160290772405381502417265830",
                "67887943793448817886930941070115941163"
            ]
        },
        "deprecated": false,
        "id": "CVE-2016-7133-b6ee4d35",
        "signature_type": "Line"
    }
]