Description
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.
Remediation
References
Related Vulnerabilities
WordPress Plugin Login with Azure (Azure SSO) Cross-Site Scripting (1.4.4)
WordPress Plugin WP Reroute Email Cross-Site Request Forgery (1.4.6)
WordPress Plugin Ultimate Category Excluder Cross-Site Request Forgery (1.1)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2018-17189)
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2023-4006)