{"id":"CVE-2016-5114","details":"sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and buffer overflow) via a long string, as demonstrated by a long URI in a configuration with custom REQUEST_URI logging.","modified":"2026-08-07T14:48:24.276246Z","published":"2016-08-07T10:59:10.947Z","related":["SUSE-SU-2016:1581-1","SUSE-SU-2016:1638-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:php:php:5.6.0:alpha4:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.0:alpha5:*:*:*:*:*:*"],"extracted_events":[{"introduced":"5.6.0-alpha4"},{"last_affected":"5.6.0-alpha4"},{"introduced":"5.6.0-alpha5"},{"last_affected":"5.6.0-alpha5"}],"source":"CPE_STRING","vendor_product":"php:php"}]},"references":[{"type":"WEB","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2750.html"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/05/29/1"},{"type":"FIX","url":"http://github.com/php/php-src/commit/2721a0148649e07ed74468f097a28899741eb58f?w=1"},{"type":"FIX","url":"http://php.net/ChangeLog-5.php"},{"type":"FIX","url":"http://php.net/ChangeLog-7.php"},{"type":"FIX","url":"http://www.search-lab.hu/about-us/news/111-some-unusual-vulnerabilities-in-the-php-engine"},{"type":"EVIDENCE","url":"https://bugs.php.net/bug.php?id=70755"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"0"},{"last_affected":"82d537811cffa2851bae985b47b2ba91818f0c58"},{"introduced":"8648f76bac2f78391a1539253f21d62f53d83022"},{"last_affected":"4054ec69da7631046f19d54ab06f09728a208b8b"},{"fixed":"2721a0148649e07ed74468f097a28899741eb58f"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.0:alpha2:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.0:alpha3:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.0:beta1:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.0:beta2:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.0:beta3:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.0:beta4:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.2:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.3:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.4:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.5:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.6:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.7:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.8:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.9:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.10:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.11:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.12:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.13:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.14:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.15:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.6.16:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"5.5.30"},{"introduced":"5.6.0-alpha1"},{"last_affected":"5.6.0-alpha1"},{"introduced":"5.6.0-alpha2"},{"last_affected":"5.6.0-alpha2"},{"introduced":"5.6.0-alpha3"},{"last_affected":"5.6.0-alpha3"},{"introduced":"5.6.0-beta1"},{"last_affected":"5.6.0-beta1"},{"introduced":"5.6.0-beta2"},{"last_affected":"5.6.0-beta2"},{"introduced":"5.6.0-beta3"},{"last_affected":"5.6.0-beta3"},{"introduced":"5.6.0-beta4"},{"last_affected":"5.6.0-beta4"},{"introduced":"5.6.1"},{"last_affected":"5.6.1"},{"introduced":"5.6.2"},{"last_affected":"5.6.2"},{"introduced":"5.6.3"},{"last_affected":"5.6.3"},{"introduced":"5.6.4"},{"last_affected":"5.6.4"},{"introduced":"5.6.5"},{"last_affected":"5.6.5"},{"introduced":"5.6.6"},{"last_affected":"5.6.6"},{"introduced":"5.6.7"},{"last_affected":"5.6.7"},{"introduced":"5.6.8"},{"last_affected":"5.6.8"},{"introduced":"5.6.9"},{"last_affected":"5.6.9"},{"introduced":"5.6.10"},{"last_affected":"5.6.10"},{"introduced":"5.6.11"},{"last_affected":"5.6.11"},{"introduced":"5.6.12"},{"last_affected":"5.6.12"},{"introduced":"5.6.13"},{"last_affected":"5.6.13"},{"introduced":"5.6.14"},{"last_affected":"5.6.14"},{"introduced":"5.6.15"},{"last_affected":"5.6.15"},{"introduced":"5.6.16"},{"last_affected":"5.6.16"},{"introduced":"7.0.0"},{"last_affected":"7.0.0"},{"introduced":"7.0.1"},{"last_affected":"7.0.1"}]}}],"versions":["5.6.0-alpha1","5.6.0-alpha2","5.6.0-alpha3","5.6.0-beta1","5.6.0-beta2","5.6.0-beta3","5.6.0-beta4","5.6.1","5.6.10","5.6.11","5.6.12","5.6.13","5.6.14","5.6.15","5.6.16","5.6.2","5.6.3","5.6.4","5.6.5","5.6.6","5.6.7","5.6.8","5.6.9","7.0.0","7.0.1","php-7.0.2RC1","php-7.0.1","php-7.0.1RC1","php-5.5.30","POST_PHP7_NSAPI_REMOVAL","PRE_PHP7_NSAPI_REMOVAL","PRE_PHP7_EREG_MYSQL_REMOVALS","PRE_PHP7_REMOVALS","POST_PHP7_REMOVALS","POST_AST_MERGE","PRE_AST_MERGE","POST_64BIT_BRANCH_MERGE","PRE_64BIT_BRANCH_MERGE","POST_PHPNG_MERGE"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/php/php-src/commit/2721a0148649e07ed74468f097a28899741eb58f","target":{"file":"sapi/fpm/fpm/fpm_log.c"},"deprecated":false,"digest":{"line_hashes":["173546673262426173184942032182949250695","321622208661209477458049574569903221220","166444530145029150694248049069211197840","205433036944475656471158298503614011224"],"threshold":0.9},"id":"CVE-2016-5114-2b4d9166","signature_type":"Line"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/php/php-src/commit/2721a0148649e07ed74468f097a28899741eb58f","target":{"file":"sapi/fpm/fpm/fpm_log.c","function":"fpm_log_write"},"deprecated":false,"digest":{"function_hash":"18497476000700736301362621056643006825","length":7950},"id":"CVE-2016-5114-e692c715"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5114.json","vanir_signatures_modified":"2026-08-07T14:48:24Z"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}