Description
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
Remediation
References
Related Vulnerabilities
Envoy Proxy Reachable Assertion Vulnerability (CVE-2021-29258)
Oracle Database Server Other Vulnerability (CVE-2005-3446)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3397)
GlassFish Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3250)