Description
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.
Remediation
References
Related Vulnerabilities
GlassFish CVE-2016-5519 Vulnerability (CVE-2016-5519)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2016-8627)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10268)
WordPress Plugin Auto Post to Social Media-WordPress to Buffer Cross-Site Scripting (3.7.4)