Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-21704

Опубликовано: 04 окт. 2021
Источник: debian
EPSS Низкий

Описание

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.0fixed8.0.8-1package
php7.4fixed7.4.21-1+deb11u1package
php7.3removedpackage
php7.0removedpackage

Примечания

  • Fixed in 8.0.8, 7.4.21, 7.3.29

  • PHP Bug: https://bugs.php.net/76448

  • PHP Bug: https://bugs.php.net/76449

  • PHP Bug: https://bugs.php.net/76450

  • PHP Bug: https://bugs.php.net/76452

EPSS

Процентиль: 34%
0.00131
Низкий

Связанные уязвимости

CVSS3: 5
ubuntu
около 4 лет назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

CVSS3: 5.9
redhat
больше 4 лет назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

CVSS3: 5
nvd
около 4 лет назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

CVSS3: 5
msrc
около 1 месяца назад

Multiple vulnerabilities in Firebird client extension

suse-cvrf
около 4 лет назад

Security update for php7

EPSS

Процентиль: 34%
0.00131
Низкий