Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

nvd Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2017-8923

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 12 мая 2017
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

ОписаниС

The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.

Бсылки

УязвимыС ΠΊΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΠΈ

ΠšΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΡ 1

Одно из

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
ВСрсия Π΄ΠΎ 7.4.24 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
ВСрсия ΠΎΡ‚ 8.0.0 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 8.0.11 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 89%
0.04586
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Π”Π΅Ρ„Π΅ΠΊΡ‚Ρ‹

CWE-787

БвязанныС уязвимости

CVSS3: 9.8
ubuntu
ΠΏΠΎΡ‡Ρ‚ΠΈ 9 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.

CVSS3: 7.5
redhat
ΠΏΠΎΡ‡Ρ‚ΠΈ 9 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.

CVSS3: 9.8
msrc
6 мСсяцСв Π½Π°Π·Π°Π΄

The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.

CVSS3: 9.8
debian
ΠΏΠΎΡ‡Ρ‚ΠΈ 9 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

The zend_string_extend function in Zend/zend_string.h in PHP through 7 ...

suse-cvrf
ΠΎΠΊΠΎΠ»ΠΎ 4 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Security update for php7

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 89%
0.04586
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Π”Π΅Ρ„Π΅ΠΊΡ‚Ρ‹

CWE-787
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2017-8923