Описание
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.
| Релиз | Статус | Примечание | 
|---|---|---|
| artful | DNE  | |
| bionic | DNE  | |
| cosmic | DNE  | |
| devel | DNE  | |
| disco | DNE  | |
| eoan | DNE  | |
| esm-infra-legacy/trusty | needed  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| groovy | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| artful | DNE  | |
| bionic | DNE  | |
| cosmic | DNE  | |
| devel | DNE  | |
| disco | DNE  | |
| eoan | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| esm-infra/xenial | released  | 7.0.33-0ubuntu0.16.04.16+esm3 | 
| focal | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| artful | DNE  | |
| bionic | released  | 7.2.24-0ubuntu0.18.04.11 | 
| cosmic | ignored  | end of life | 
| devel | DNE  | |
| disco | ignored  | end of life | 
| eoan | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/bionic | released  | 7.2.24-0ubuntu0.18.04.11 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | released  | 7.4.3-4ubuntu2.10 | 
| focal | released  | 7.4.3-4ubuntu2.10 | 
| impish | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| impish | released  | 8.0.8-1ubuntu0.3 | 
| jammy | DNE  | |
| kinetic | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| impish | DNE  | |
| jammy | not-affected  | 8.1.0-1 | 
| kinetic | not-affected  | 8.1.0-1 | 
| lunar | not-affected  | 8.1.0-1 | 
| mantic | DNE  | 
Показывать по
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.
The zend_string_extend function in Zend/zend_string.h in PHP through 7 ...
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3