Critical severity9.8NVD Advisory· Published Aug 7, 2016· Updated Jun 17, 2026
CVE-2016-5773
CVE-2016-5773
Description
php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
58cpe:2.3:a:php:php:*:*:*:*:*:*:*:*+ 41 more
- cpe:2.3:a:php:php:*:*:*:*:*:*:*:*range: <=5.5.36
- cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.0:alpha4:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.0:alpha5:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.10:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.11:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.12:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.13:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.14:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.15:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.16:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.17:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.18:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.19:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.20:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.21:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.22:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.23:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.6:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.7:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.8:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:5.6.9:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*
- (no CPE)range: <5.5.37 || (5.6.0 < 5.6.23) || (7.0.0 < 7.0.8)
- osv-coords16 versionspkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2
< 2007e_suse-22.1+ 15 more
- (no CPE)range: < 2007e_suse-22.1
- (no CPE)range: < 2007e_suse-22.1
- (no CPE)range: < 2007e_suse-22.1
- (no CPE)range: < 2007e_suse-22.1
- (no CPE)range: < 2007e_suse-22.1
- (no CPE)range: < 2007e_suse-22.1
- (no CPE)range: < 2007e_suse-22.1
- (no CPE)range: < 5.3.17-112.20.1
- (no CPE)range: < 5.3.17-112.20.1
- (no CPE)range: < 5.3.17-112.20.1
- (no CPE)range: < 5.3.17-112.20.1
- (no CPE)range: < 5.3.17-112.20.1
- (no CPE)range: < 5.3.17-112.20.1
- (no CPE)range: < 5.5.14-86.2
- (no CPE)range: < 5.5.14-86.2
- (no CPE)range: < 5.5.14-86.2
Patches
Vulnerability mechanics
References
12- php.net/ChangeLog-5.phpnvdPatchRelease Notes
- php.net/ChangeLog-7.phpnvdPatchRelease Notes
- bugs.php.net/bug.phpnvdExploitVendor Advisory
- www.openwall.com/lists/oss-security/2016/06/23/4nvdRelease Notes
- github.com/php/php-src/commit/f6aef68089221c5ea047d4a74224ee3deead99a6nvd
- lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-07/msg00004.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-2750.htmlnvd
- www.debian.org/security/2016/dsa-3618nvd
- www.securityfocus.com/bid/91397nvd
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvd
- support.apple.com/HT207170nvd
News mentions
0No linked articles in our index yet.