Zend/zendalloc.c in PHP 7.x before 7.0.10, when openbasedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.
[
{
"signature_version": "v1",
"target": {
"function": "zend_mm_realloc_heap",
"file": "Zend/zend_alloc.c"
},
"source": "https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911",
"digest": {
"length": 5848.0,
"function_hash": "38175289135737973986616221052495021956"
},
"deprecated": false,
"id": "CVE-2016-7133-44c094ca",
"signature_type": "Function"
},
{
"signature_version": "v1",
"target": {
"file": "Zend/zend_alloc.c"
},
"source": "https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911",
"digest": {
"threshold": 0.9,
"line_hashes": [
"111961339304292541928537430669186257034",
"210124735288199671747588466160865165662",
"205982916566899775144936522917698108524",
"110388679627889035768047294777568249569",
"3170154757877869724997979614184162861",
"63456613087521314659647146272467556526",
"1906302105730951111839831544056783248",
"102314375066585841612098046167144926817",
"257177565617055216047557024224075629103",
"127954140771692017760430304661574497539",
"164390002335094048823598899959093131430",
"259951822483819625095797803158310720835",
"266711533443493267362270896471606063165",
"254621335695541198791336833240291131338",
"319646960869429078803581925529288413616",
"296482086816160290772405381502417265830",
"67887943793448817886930941070115941163"
]
},
"deprecated": false,
"id": "CVE-2016-7133-b6ee4d35",
"signature_type": "Line"
}
]