Description
Integer overflow in the fread function in ext/standard/file.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer in the second argument.
Remediation
References
Related Vulnerabilities
e107 Other Vulnerability (CVE-2004-2042)
Oracle Database Server CVE-2009-1021 Vulnerability (CVE-2009-1021)
WordPress Plugin PowerPress Podcasting by Blubrry SQL Injection (6.0.2)
WordPress Plugin File Groups 'fgid' Parameter SQL Injection (1.1.2)
Squid Improper Input Validation Vulnerability (CVE-2020-25097)