The following flaw was found in PHP: PHPAPI php_check_specific_open_basedir in php-src/main/fopen_wrappers.c has a integer overflow vulnerability leads to buffer overflow if open_basedir is set. A remote attacker could use this flaw to crash a PHP application. Upstream bug: https://bugs.php.net/bug.php?id=72742 Upstream patch: https://github.com/php/php-src/commit/c2a13ced4272f2e65d2773e2ea6ca11c1ce4a911?w=1