Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions cause a denial of service or execute arbitrary code via (1) a negative offset value to the shmop_write function (2) an \integer overflow/underflow\ in the pack function or (3) an \integer overflow/underflow\ in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.