In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact within International Components for Unicode (ICU) for C/C++ via a long first argument to the msgfmt_parse_message function.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Jul 17, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade php-cliUpgrade php-gdUpgrade phpUpgrade php-xmlrpcUpgrade php-pdoUpgrade php-recodeUpgrade php-xmlUpgrade php-ldapUpgrade php-processUpgrade php-soapUpgrade php-pgsqlUpgrade php-commonUpgrade php-odbcUpgrade php-mysql | Nov 3, 2020 | Jul 17, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade php-soapUpgrade php-processUpgrade php-pgsqlUpgrade php-gdUpgrade php-mysqlUpgrade php-xmlrpcUpgrade php-pdoUpgrade php-ldapUpgrade php-commonUpgrade php-odbcUpgrade phpUpgrade php-recodeUpgrade php-xmlUpgrade php-cli | Sep 28, 2020 | Jul 17, 2017 |
| Php | — | Upgrade to PHP version 7.1.7Upgrade to PHP version 7.0.21 | Jul 31, 2017 | Jul 17, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 17, 2017 |
| Ubuntu | — | Upgrade php5-fpmUpgrade libapache2-mod-php7.0Upgrade php7.0-cliUpgrade libapache2-mod-php5Upgrade php7.0-cgiUpgrade php7.0-fpmUpgrade php5-cliUpgrade php5-cgi | Aug 10, 2017 | Jul 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub