Back

CRITICAL

php: Integer Overflows in mcrypt_generic() and mdecrypt_generic() resulting in heap overflows

Published Aug 7, 2016

Description

Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted length value, related to the (1) mcrypt_generic and (2) mdecrypt_generic functions.

Affected products

Remediation

Red Hat statement

The versions of PHP package shipped with Red Hat Enterprise Linux, do not have support for mcrypt.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 7, 2016
Updated Aug 6, 2024
Reserved Jun 23, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 23, 2016