The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5, mishandles continuation-level jumps, which allows context-dependent attackers to cause a denial of service (buffer overflow and application crash) or possibly execute arbitrary code via a crafted magic file.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade php56Upgrade php55 | May 3, 2016 | May 3, 2016 |
| Apple Osx Apachemodphp | — | Upgrade macOS to the latest version | Jun 2, 2016 | May 20, 2016 |
| Debian | — | Upgrade php5Upgrade file | Apr 28, 2016 | Apr 27, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jun 10, 2016 |
| Gentoo Linux | — | Upgrade dev-lang/php.Upgrade sys-apps/file. | Oct 30, 2017 | May 20, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade php-gdUpgrade php-recodeUpgrade php-soapUpgrade php-ldapUpgrade php-processUpgrade phpUpgrade php-pdoUpgrade php-xmlrpcUpgrade php-xmlUpgrade php-pgsqlUpgrade php-cliUpgrade php-mysqlUpgrade php-commonUpgrade php-odbc | Sep 12, 2019 | May 20, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade php-commonUpgrade php-recodeUpgrade php-cliUpgrade phpUpgrade php-xmlrpcUpgrade php-xmlUpgrade php-gdUpgrade php-soapUpgrade php-ldapUpgrade php-pdoUpgrade php-processUpgrade php-odbcUpgrade php-mysqlUpgrade php-pgsql | Sep 25, 2019 | May 20, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade php-xmlrpcUpgrade php-soapUpgrade php-pgsqlUpgrade php-mysqlUpgrade php-processUpgrade php-gdUpgrade php-ldapUpgrade php-odbcUpgrade php-cliUpgrade php-xmlUpgrade php-pdoUpgrade php-recodeUpgrade php-commonUpgrade php | Aug 16, 2019 | May 20, 2016 |
| Php | — | Upgrade to PHP version 5.5.34Upgrade to PHP version 7.0.5Upgrade to PHP version 5.6.20 | Jun 3, 2016 | May 20, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 23, 2016 |
| Ubuntu | — | Upgrade libapache2-mod-php7.0Upgrade php7.0-cgiUpgrade php7.0-cliUpgrade fileUpgrade libmagic1Upgrade php7.0-fpm | May 24, 2016 | May 20, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub