Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-17082

Опубликовано: 16 сент. 2018
Источник: debian
EPSS Средний

Описание

The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.3fixed7.3.0~rc2-1package
php7.2unfixedpackage
php7.1removedpackage
php7.0fixed7.0.32-1package
php5removedpackage

Примечания

  • Fixed in 5.6.38, 7.0.32, 7.1.22, 7.2.10, 7.3.0RC1

  • PHP Bug: https://bugs.php.net/bug.php?id=76582

  • https://github.com/php/php-src/commit/23b057742e3cf199612fa8050ae86cae675e214e

EPSS

Процентиль: 96%
0.24219
Средний

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 7 лет назад

The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.

CVSS3: 4.7
redhat
почти 7 лет назад

The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.

CVSS3: 6.1
nvd
почти 7 лет назад

The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.

suse-cvrf
больше 6 лет назад

Security update for php7

suse-cvrf
больше 6 лет назад

Security update for php5

EPSS

Процентиль: 96%
0.24219
Средний