The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5, mishandles continuation-level jumps, which allows context-dependent attackers to cause a denial of service (buffer overflow and application crash) or possibly execute arbitrary code via a crafted magic file.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade php56Upgrade php55 | May 3, 2016 | May 3, 2016 |
| Apple Osx Apachemodphp | — | Upgrade macOS to the latest version | Jun 2, 2016 | May 20, 2016 |
| Debian | — | Upgrade fileUpgrade php5 | Apr 28, 2016 | Apr 27, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jun 10, 2016 |
| Gentoo Linux | — | Upgrade sys-apps/file.Upgrade dev-lang/php. | Oct 30, 2017 | May 20, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade php-odbcUpgrade php-commonUpgrade php-cliUpgrade php-mysqlUpgrade php-pgsqlUpgrade php-xmlUpgrade php-recodeUpgrade php-processUpgrade php-gdUpgrade php-xmlrpcUpgrade php-ldapUpgrade php-pdoUpgrade phpUpgrade php-soap | Sep 12, 2019 | May 20, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade php-xmlrpcUpgrade php-xmlUpgrade php-recodeUpgrade php-cliUpgrade php-commonUpgrade phpUpgrade php-gdUpgrade php-pgsqlUpgrade php-soapUpgrade php-odbcUpgrade php-ldapUpgrade php-mysqlUpgrade php-processUpgrade php-pdo | Sep 25, 2019 | May 20, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade php-commonUpgrade php-recodeUpgrade php-odbcUpgrade php-cliUpgrade php-pdoUpgrade php-xmlUpgrade phpUpgrade php-ldapUpgrade php-xmlrpcUpgrade php-gdUpgrade php-soapUpgrade php-pgsqlUpgrade php-processUpgrade php-mysql | Aug 16, 2019 | May 20, 2016 |
| Php | — | Upgrade to PHP version 5.6.20Upgrade to PHP version 5.5.34Upgrade to PHP version 7.0.5 | Jun 3, 2016 | May 20, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 23, 2016 |
| Ubuntu | — | Upgrade php7.0-fpmUpgrade php7.0-cgiUpgrade libapache2-mod-php7.0Upgrade php7.0-cliUpgrade fileUpgrade libmagic1 | May 24, 2016 | May 20, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub