Description
Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.
Remediation
References
Related Vulnerabilities
WordPress Plugin Filter Custom Fields & Taxonomies Light Unspecified Vulnerability (1.04)
WordPress Plugin Stock Ticker Security Bypass (3.23.0)
WordPress Plugin Events Manager Cross-Site Request Forgery (5.9.8.1)
WordPress Plugin Font-official webfonts plugin of Fonts For Web Directory Traversal (7.5)