php: Integer overflow in php_raw_url_encode
Published May 20, 2016
7.5
HIGHCVSS 3.0
EPSS 5.72%
Description
Integer overflow in the php_raw_url_encode function in ext/standard/url.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to cause a denial of service (application crash) via a long string to the rawurlencode function. NOTE: the vendor says "Not sure if this qualifies as security issue (probably not).
Affected products
No data.
- ≤ 5.5.33
- 5.6.0
- 5.6.0
- 5.6.0
- 5.6.0
- 5.6.0
- 5.6.0
- 5.6.0
- 5.6.0
- 5.6.0
- 5.6.1
- 5.6.2
- 5.6.3
- 5.6.4
- 5.6.5
- 5.6.6
- 5.6.7
- 5.6.8
- 5.6.9
- 5.6.10
- 5.6.11
- 5.6.12
- 5.6.13
- 5.6.14
- 5.6.15
- 5.6.16
- 5.6.17
- 5.6.18
- 5.6.19
- 7.0.0
- 7.0.1
- 7.0.2
- 7.0.3
- 7.0.4
No data.
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php56-0:2.3-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php56-php-0:5.6.25-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php56-php-pear-1:1.9.5-4.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-php56-0:2.3-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-php56-php-0:5.6.25-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-php56-php-pear-1:1.9.5-4.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php56-0:2.3-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php56-php-0:5.6.25-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php56-php-pear-1:1.9.5-4.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-php56-0:2.3-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-php56-php-0:5.6.25-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-php56-php-pear-1:1.9.5-4.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-php56-0:2.3-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-php56-php-0:5.6.25-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-php56-php-pear-1:1.9.5-4.el7
Fixed · RHSA-2016:2750
Red Hat Enterprise Linux 5
php
Will not fix
Red Hat Enterprise Linux 5
php53
Will not fix
Red Hat Enterprise Linux 6
php
Affected
Red Hat Enterprise Linux 7
php
Affected
Red Hat Software Collections
php54-php
Will not fix
Red Hat Software Collections
php55-php
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-0:2.3-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php-0:5.6.25-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php-pear-1:1.9.5-4.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56-0:2.3-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56-php-0:5.6.25-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56-php-pear-1:1.9.5-4.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php56-0:2.3-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php56-php-0:5.6.25-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php56-php-pear-1:1.9.5-4.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-php56-0:2.3-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-php56-php-0:5.6.25-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-php56-php-pear-1:1.9.5-4.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-php56-0:2.3-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-php56-php-0:5.6.25-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-php56-php-pear-1:1.9.5-4.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Enterprise Linux 5 | php | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | php53 | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | php | Affected | n/a |
| Red Hat Enterprise Linux 7 | php | Affected | n/a |
| Red Hat Software Collections | php54-php | Will not fix | n/a |
| Red Hat Software Collections | php55-php | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 18, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.72% (0.05719) | 92.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.72% (0.05719) | 92.02th | v5 (v2026.06.15) |
| Dec 28, 2025 | 6.47% (0.06468) | 90.75th | v4 (v2025.03.14) |
| Dec 27, 2025 | 4.08% (0.04078) | 88.25th | v4 (v2025.03.14) |
| Oct 28, 2025 | 6.47% (0.06468) | 90.64th | v4 (v2025.03.14) |
| Oct 27, 2025 | 4.08% (0.04078) | 88.09th | v4 (v2025.03.14) |
| Oct 1, 2025 | 6.47% (0.06468) | 90.74th | v4 (v2025.03.14) |
| Sep 14, 2025 | 4.08% (0.04078) | 88.11th | v4 (v2025.03.14) |
| Aug 20, 2025 | 9.17% (0.09173) | 92.35th | v4 (v2025.03.14) |
| Jul 30, 2025 | 6.23% (0.06231) | 90.51th | v4 (v2025.03.14) |
| Jun 21, 2025 | 11.17% (0.11172) | 93.15th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.38% (0.05381) | 89.13th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.71% (0.07712) | 86.25th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.38% (0.05381) | 89.39th | v4 (v2025.03.14) |
| Dec 17, 2024 | 24.23% (0.24230) | 96.63th | v3 (v2023.03.01) |
| Aug 20, 2024 | 30.74% (0.30739) | 97.03th | v3 (v2023.03.01) |
| Oct 31, 2023 | 24.23% (0.24230) | 96.07th | v3 (v2023.03.01) |
| Aug 21, 2023 | 26.04% (0.26035) | 96.12th | v3 (v2023.03.01) |
| Apr 23, 2023 | 20.18% (0.20181) | 95.59th | v3 (v2023.03.01) |
| Mar 11, 2023 | 19.23% (0.19225) | 95.45th | v3 (v2023.03.01) |
| Mar 7, 2023 | 20.80% (0.20800) | 95.59th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.78% (0.03779) | 85.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.78% (0.03779) | 84.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.78% (0.03779) | 67.21th | v2 (v2022.01.01) |
References (22)
- http://lists.apple.com/archives/security-announce/2016/May/msg00004.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00056.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2016-2750.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2016/dsa-3560 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2016/04/24/1 mailing-listx_refsource_MLIST
- http://www.php.net/ChangeLog-5.php x_refsource_CONFIRM
- http://www.php.net/ChangeLog-7.php x_refsource_CONFIRM
- http://www.securityfocus.com/bid/85801 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2952-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2952-2 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2016-4070 Vendor Advisory
- https://bugs.php.net/bug.php?id=71798 x_refsource_CONFIRMExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=1323114 Issue Tracking
- https://git.php.net/?p=php-src.git%3Ba=commit%3Bh=95433e8e339dbb6b5d5541473c1661db6ba2c451 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2016-4070
- https://support.apple.com/HT206567 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2016-4070
Change history (0)
No recorded changes yet.