PublicDateAtUSN: 2016-07-22 Candidate: CVE-2016-5399 PublicDate: 2017-04-21 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5399 http://php.net/ChangeLog-7.php#7.0.9 https://ubuntu.com/security/notices/USN-3045-1 Description: The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive. Ubuntu-Description: Notes: seth-arnold> PHP position seems to suggest they'll fix bzread() to ensure it conforms to the documented behaviour but they won't take any steps to 'safe' an improper use of API by applications. Since the API was apparently not honoured before I don't know how an application could be expected to be correct. Bugs: https://bugs.php.net/bug.php?id=72613 Priority: medium Discovered-by: Hans Jerry Illikainen Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_php5: upstream: http://git.php.net/?p=php-src.git;a=commit;h=f3feddb5b45b5abd93abb1a95044b7e099d51c84 upstream_php5: needs-triage precise_php5: released (5.3.10-1ubuntu3.24) trusty_php5: released (5.5.9+dfsg-1ubuntu4.19) trusty/esm_php5: released (5.5.9+dfsg-1ubuntu4.19) vivid/ubuntu-core_php5: DNE vivid/stable-phone-overlay_php5: DNE wily_php5: ignored (reached end-of-life) xenial_php5: DNE devel_php5: DNE Patches_php7.0: upstream: http://git.php.net/?p=php-src.git;a=commit;h=f3feddb5b45b5abd93abb1a95044b7e099d51c84 upstream_php7.0: released (7.0.9) precise_php7.0: DNE trusty_php7.0: DNE trusty/esm_php7.0: DNE vivid/ubuntu-core_php7.0: DNE vivid/stable-phone-overlay_php7.0: DNE wily_php7.0: DNE xenial_php7.0: released (7.0.8-0ubuntu0.16.04.2) esm-infra/xenial_php7.0: released (7.0.8-0ubuntu0.16.04.2) devel_php7.0: released (7.0.8-3ubuntu2)