The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.
[
{
"deprecated": false,
"source": "https://github.com/php/php-src/commit/9d582eba7448f1495fae62b13d95d2844ce6b28a",
"id": "CVE-2016-5399-b7259250",
"target": {
"file": "ext/standard/basic_functions.c"
},
"digest": {
"line_hashes": [
"198011536025072107975883186380452148843",
"331728417024842654446570071457159069395",
"205456331668105326830182380336029223146",
"164282985402725457749299583506046134408",
"320137256578601229186691392718001358014"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5399.json"