Description
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2010-3600 Vulnerability (CVE-2010-3600)
Ampache Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-3929)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2146)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-3542)