A format string vulnerability in php-7.0.0 was found, due to how non-existent class names are handled. This issue is potentially exploitable for code execution. Upstream bug: https://bugs.php.net/bug.php?id=71105 Upstream patch: https://github.com/php/php-src/commit/b101a6bbd4f2181c360bd38e7683df4a03cba83e CVE assignment: http://seclists.org/oss-sec/2015/q4/561