CVE-2016-7133

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-7133
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7133.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-7133
Downstream
Related
Published
2016-09-12T01:59:11Z
Modified
2025-09-19T08:33:51.094256Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Zend/zendalloc.c in PHP 7.x before 7.0.10, when openbasedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.

References

Affected packages

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

NEWS
NEWS-cvs2svn
POST_64BIT_BRANCH_MERGE
POST_AST_MERGE
POST_NATIVE_TLS_MERGE
POST_PHP7_EREG_MYSQL_REMOVALS
POST_PHP7_NSAPI_REMOVAL
POST_PHP7_REMOVALS
POST_PHPNG_MERGE
PRE_64BIT_BRANCH_MERGE
PRE_AST_MERGE
PRE_NATIVE_TLS_MERGE
PRE_PHP7_EREG_MYSQL_REMOVALS
PRE_PHP7_NSAPI_REMOVAL
PRE_PHP7_REMOVALS
PRE_PHPNG_MERGE

php-5.*

php-5.3.23RC1
php-5.3.29
php-5.3.29RC1
php-5.4.30RC1
php-5.4.32RC1
php-5.4.4RC2
php-5.5.24RC1
php-5.6.18RC1
php-5.6.19RC1
php-5.6.22RC1
php-5.6.23RC1
php-5.6.24RC1

php-7.*

php-7.0.3RC1
php-7.0.4RC1
php-7.0.5RC1
php-7.0.7RC1
php-7.0.8RC1
php-7.0.9RC1

Database specific

{
    "vanir_signatures": [
        {
            "deprecated": false,
            "source": "https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911",
            "target": {
                "function": "zend_mm_realloc_heap",
                "file": "Zend/zend_alloc.c"
            },
            "digest": {
                "function_hash": "38175289135737973986616221052495021956",
                "length": 5848.0
            },
            "id": "CVE-2016-7133-44c094ca",
            "signature_version": "v1",
            "signature_type": "Function"
        },
        {
            "deprecated": false,
            "source": "https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911",
            "target": {
                "file": "Zend/zend_alloc.c"
            },
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "111961339304292541928537430669186257034",
                    "210124735288199671747588466160865165662",
                    "205982916566899775144936522917698108524",
                    "110388679627889035768047294777568249569",
                    "3170154757877869724997979614184162861",
                    "63456613087521314659647146272467556526",
                    "1906302105730951111839831544056783248",
                    "102314375066585841612098046167144926817",
                    "257177565617055216047557024224075629103",
                    "127954140771692017760430304661574497539",
                    "164390002335094048823598899959093131430",
                    "259951822483819625095797803158310720835",
                    "266711533443493267362270896471606063165",
                    "254621335695541198791336833240291131338",
                    "319646960869429078803581925529288413616",
                    "296482086816160290772405381502417265830",
                    "67887943793448817886930941070115941163"
                ]
            },
            "id": "CVE-2016-7133-b6ee4d35",
            "signature_version": "v1",
            "signature_type": "Line"
        }
    ]
}