The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5, mishandles continuation-level jumps, which allows context-dependent attackers to cause a denial of service (buffer overflow and application crash) or possibly execute arbitrary code via a crafted magic file.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade php55Upgrade php56 | May 3, 2016 | May 3, 2016 |
| Apple Osx Apachemodphp | — | Upgrade macOS to the latest version | Jun 2, 2016 | May 20, 2016 |
| Debian | — | Upgrade fileUpgrade php5 | Apr 28, 2016 | Apr 27, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jun 10, 2016 |
| Gentoo Linux | — | Upgrade dev-lang/php.Upgrade sys-apps/file. | Oct 30, 2017 | May 20, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade php-ldapUpgrade php-pdoUpgrade php-soapUpgrade php-xmlrpcUpgrade php-gdUpgrade phpUpgrade php-processUpgrade php-recodeUpgrade php-commonUpgrade php-cliUpgrade php-xmlUpgrade php-pgsqlUpgrade php-odbcUpgrade php-mysql | Sep 12, 2019 | May 20, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade php-xmlUpgrade php-xmlrpcUpgrade php-commonUpgrade php-cliUpgrade php-recodeUpgrade phpUpgrade php-pdoUpgrade php-soapUpgrade php-mysqlUpgrade php-ldapUpgrade php-processUpgrade php-odbcUpgrade php-gdUpgrade php-pgsql | Sep 25, 2019 | May 20, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade php-pgsqlUpgrade php-processUpgrade php-mysqlUpgrade php-gdUpgrade php-xmlrpcUpgrade php-soapUpgrade phpUpgrade php-odbcUpgrade php-recodeUpgrade php-commonUpgrade php-ldapUpgrade php-xmlUpgrade php-cliUpgrade php-pdo | Aug 16, 2019 | May 20, 2016 |
| Php | — | Upgrade to PHP version 7.0.5Upgrade to PHP version 5.6.20Upgrade to PHP version 5.5.34 | Jun 3, 2016 | May 20, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 23, 2016 |
| Ubuntu | — | Upgrade fileUpgrade php7.0-cgiUpgrade libmagic1Upgrade php7.0-cliUpgrade libapache2-mod-php7.0Upgrade php7.0-fpm | May 24, 2016 | May 20, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub