Description
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted call to (1) getFromIndex or (2) getFromName in the ZipArchive class.
Remediation
References
Related Vulnerabilities
WordPress 3.8.x Arbitrary File Deletion Vulnerability (3.8 - 3.8.26)
ownCloud CVE-2017-9340 Vulnerability (CVE-2017-9340)
WordPress Plugin Ooorl Cross-Site Scripting (1.0.0)
MySQL CVE-2023-22038 Vulnerability (CVE-2023-22038)
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Multiple Vulnerabilities (1.17.1)