HTTP: PHP ZipArchive getFromIndex and getFromName Integer Overflow
This signature detects attempts to exploit a known vulnerability in PHP. A successful attack can lead to arbitrary code execution.
Extended Description
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted call to (1) getFromIndex or (2) getFromName in the ZipArchive class.
Affected Products
Php php
References
CVE: CVE-2016-3078
URL: http://securitytracker.com/id?1035701 https://bugs.php.net/bug.php?id=71923
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Php
7.5