Описание
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | not-affected | 5.5.9+dfsg-1ubuntu4.26 |
precise/esm | not-affected | 5.3.10-1ubuntu3.32 |
trusty | released | 5.5.9+dfsg-1ubuntu4.26 |
trusty/esm | not-affected | 5.5.9+dfsg-1ubuntu4.26 |
upstream | released | 5.6.38 |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/xenial | not-affected | 7.0.32-0ubuntu0.16.04.1 |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 7.0.32 |
xenial | released | 7.0.32-0ubuntu0.16.04.1 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 7.2.10-0ubuntu0.18.04.1 |
devel | released | 7.2.10-0ubuntu1 |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | not-affected | 7.2.10-0ubuntu0.18.04.1 |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 7.2.10 |
xenial | DNE |
Показывать по
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x ...
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3