Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
| Software | From | Fixed in |
|---|---|---|
| php / php | 7.0.0 | 7.0.4 |
| opensuse / leap | 42.1 | 42.1.x |
| opensuse / opensuse | 13.2 | 13.2.x |