Loading HuntDB...

GHSA-m5g2-hw2w-vfvh

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allows remote MySQL servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted field metadata.

Related CVEs

Key Information

GHSA ID
GHSA-m5g2-hw2w-vfvh
Published
May 14, 2022 3:27 AM
Last Modified
May 14, 2022 3:27 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.