Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21702

Опубликовано: 26 янв. 2021
Источник: redhat
CVSS3: 7.5

Описание

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

A NULL pointer dereference issue is in the SOAP extension of PHP. More specifically, the flaw occurs in the SoapClient when parsing a WSDL document due to improper checking of a child node name. A malicious or compromised server replies with a crafted WSDL document, leading to a denial of service of the SoapClient accessing said document. The highest threat from this vulnerability is to system availability.

Отчет

This flaw has been rated as having a security impact of Low, because it requires a malicious or compromised server in order to be exploited, and it only affects the SOAP client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5phpOut of support scope
Red Hat Enterprise Linux 5php53Out of support scope
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpOut of support scope
Red Hat Enterprise Linux 8php:7.2/phpFix deferred
Red Hat Enterprise Linux 8php:7.3/phpFix deferred
Red Hat Enterprise Linux 9phpNot affected
Red Hat Enterprise Linux 8phpFixedRHSA-2021:421309.11.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-php73-phpFixedRHSA-2021:299203.08.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-php73-phpFixedRHSA-2021:299203.08.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1925272php: NULL pointer dereference in SoapClient

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

CVSS3: 5.3
nvd
больше 4 лет назад

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

CVSS3: 5.3
debian
больше 4 лет назад

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below ...

suse-cvrf
больше 4 лет назад

Security update for php7

suse-cvrf
больше 4 лет назад

Security update for php53

7.5 High

CVSS3