VYPR
High severity8.1NVD Advisory· Published Sep 17, 2016· Updated May 6, 2026

CVE-2016-7412

CVE-2016-7412

Description

ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allows remote MySQL servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted field metadata.

Affected products

12
  • PHP/PHP12 versions
    cpe:2.3:a:php:php:*:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*range: <=5.6.25
    • cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.