Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-21702

Опубликовано: 15 фев. 2021
Источник: debian
EPSS Низкий

Описание

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.0fixed8.0.2-1package
php7.4fixed7.4.15-1package
php7.3removedpackage
php7.0removedpackage

Примечания

  • Fixed in PHP 8.0.2, 7.4.15, 7.3.27

  • PHP Bug: https://bugs.php.net/80672

EPSS

Процентиль: 38%
0.00159
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

CVSS3: 7.5
redhat
больше 4 лет назад

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

CVSS3: 5.3
nvd
больше 4 лет назад

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

suse-cvrf
больше 4 лет назад

Security update for php7

suse-cvrf
больше 4 лет назад

Security update for php53

EPSS

Процентиль: 38%
0.00159
Низкий