CVE-2016-7412

Source
https://cve.org/CVERecord?id=CVE-2016-7412
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7412.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-7412
Downstream
Related
Published
2016-09-17T21:59:03.900Z
Modified
2026-05-06T23:53:57.576155Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

ext/mysqlnd/mysqlndwireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNEDFLAG flag, which allows remote MySQL servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted field metadata.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "5.6.25"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.0"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.10"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.1"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.2"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.3"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.4"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.5"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.6"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.7"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.8"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "cpe": "cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*",
            "extracted_events": [
                {
                    "last_affected": "7.0.9"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "5.6.26"
                },
                {
                    "introduced": "7.x"
                },
                {
                    "fixed": "7.0.11"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7412.json"
vanir_signatures
[
    {
        "source": "https://github.com/php/php-src/commit/28f80baf3c53e267c9ce46a2a0fadbb981585132",
        "signature_version": "v1",
        "target": {
            "file": "ext/mysqlnd/mysqlnd_wireprotocol.c"
        },
        "id": "CVE-2016-7412-3762bf47",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "249684498042240104919474913087959312133",
                "294106856008990921454682331070541347290",
                "291790975272401864220714640723204659645",
                "182463667427846090686334541930162249051",
                "23221408885960602770248951632829372883",
                "102519181322775604896206692251875183170",
                "217819109308750851380110347289940526217",
                "229437743912094742651351551469076772872"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line"
    }
]
vanir_signatures_modified
"2026-05-06T23:53:57Z"