Description
Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function. NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.
Remediation
References
Related Vulnerabilities
OpenSSL Other Vulnerability (CVE-2002-0655)
WordPress Plugin bib2html Cross-Site Scripting (0.9.3)
Moodle Improper Privilege Management Vulnerability (CVE-2019-3849)
WordPress Plugin Ginger-EU Cookie Law Multiple Vulnerabilities (4.1.3)
WordPress Plugin Social Media Widget by Acurax Multiple Unspecified Vulnerabilities (3.2.3)