{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "5.6.25"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.3"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.4"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.5"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.6"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.7"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.8"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.9"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "7.0.10"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "e37064dae4a80c70405899bb591969bbe6aad9a8"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "60fffd296abce5fc071f3c173c25a2696cf683c6"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "4054ec69da7631046f19d54ab06f09728a208b8b"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "038c63cdea0472176ec2fdb162cfbd96e8c5f83e"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "4e1b8701573698f56e12672e4991d7e6239138d2"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "e09845d32614a19188632f410316478fbb440ebd"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "249a8fd9ae2324c84ede7ecfca6f6026e6d87df6"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "734a5fca2c4731e34eca551f28be9a10ffc3f3c9"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "fb59213fc461f079bc218abf44cb5e2b4db2182c"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "a36407215f69ba2debf77933dcb3faa0c3ba2d04"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "9d582eba7448f1495fae62b13d95d2844ce6b28a"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "da12ca9c1ed03084e6803f5e81e46f2e0a80460a"
            },
            {
              "fixed": "6d55ba265637d6adf0ba7e9c9ef11187d1ec2f5b"
            }
          ],
          "repo": "https://github.com/php/php-src",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a MessageFormatter::formatMessage call with a long first argument.",
  "id": "CVE-2016-7416",
  "modified": "2026-04-01T23:07:51.248536882Z",
  "published": "2016-09-17T21:59:08.107Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://www.tenable.com/security/tns-2016-19"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/bid/93008"
    },
    {
      "type": "WEB",
      "url": "http://www.securitytracker.com/id/1036836"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.php.net/ChangeLog-5.php"
    },
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2018:1296"
    },
    {
      "type": "ADVISORY",
      "url": "https://security.gentoo.org/glsa/201611-22"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.php.net/ChangeLog-7.php"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.php.net/bug.php?id=73007"
    },
    {
      "type": "FIX",
      "url": "https://github.com/php/php-src/commit/6d55ba265637d6adf0ba7e9c9ef11187d1ec2f5b?w=1"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2016/09/15/10"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}