vulnerability

Red Hat: CVE-2016-5768: Moderate: php security and bug fix update (RHSA-2016:2598)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Aug 7, 2016
Added
Nov 4, 2016
Modified
Jul 9, 2025

Description

Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by leveraging a callback exception.

Solutions

no-fix-redhat-rpm-packageredhat-upgrade-phpredhat-upgrade-php-bcmathredhat-upgrade-php-cliredhat-upgrade-php-commonredhat-upgrade-php-dbaredhat-upgrade-php-debuginforedhat-upgrade-php-develredhat-upgrade-php-embeddedredhat-upgrade-php-enchantredhat-upgrade-php-fpmredhat-upgrade-php-gdredhat-upgrade-php-intlredhat-upgrade-php-ldapredhat-upgrade-php-mbstringredhat-upgrade-php-mysqlredhat-upgrade-php-mysqlndredhat-upgrade-php-odbcredhat-upgrade-php-pdoredhat-upgrade-php-pgsqlredhat-upgrade-php-processredhat-upgrade-php-pspellredhat-upgrade-php-recoderedhat-upgrade-php-snmpredhat-upgrade-php-soapredhat-upgrade-php-xmlredhat-upgrade-php-xmlrpc
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.