PHP php_url_parse_ex DoS Vulnerability (CVE-2016-6288)
PHP php_url_parse_ex DoS Vulnerability (CVE-2016-6288)
Release date:
Updated on:
Affected Systems:
PHP <5.5.38
PHP 7.x <7.0.9
PHP 5.6.x <5.6.24
Description:
CVE (CAN) ID: CVE-2016-6288
PHP is a widely used scripting language. It is especially suitable for Web development and can be embedded into HTML.
PHP <5.5.38, ext/standard/url. c/php_url_parse_ex functions have a security vulnerability. Remote attackers can cause denial of service (stack buffer overflow ).
<* Source: PHP
*>
Suggestion:
Vendor patch:
PHP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.php.net /? Php-src.git; a = commit; h = 629e4da7cc8b174acdeab84969cbfc606a019b31
Http://php.net/ChangeLog-5.php
Https://bugs.php.net/70480
Http://php.net/ChangeLog-7.php
This article permanently updates the link address: