Description
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted call to (1) getFromIndex or (2) getFromName in the ZipArchive class.
Remediation
References
Related Vulnerabilities
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-4782)
Jboss EAP Other Vulnerability (CVE-2019-9513)
MyBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-24734)
WordPress Plugin Wise Agent Lead Capture Forms Cross-Site Scripting (1.0)