The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.
References
Configurations
History
No history.
Information
Published : 2016-07-25 14:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-6288
Mitre link : CVE-2016-6288
CVE.ORG link : CVE-2016-6288
JSON object : View
Products Affected
php
- php
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer