In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact within International Components for Unicode (ICU) for C/C++ via a long first argument to the msgfmt_parse_message function.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Jul 17, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade php-mysqlUpgrade php-commonUpgrade php-soapUpgrade php-pgsqlUpgrade php-odbcUpgrade php-xmlUpgrade php-xmlrpcUpgrade php-processUpgrade php-recodeUpgrade php-cliUpgrade php-gdUpgrade php-pdoUpgrade phpUpgrade php-ldap | Nov 3, 2020 | Jul 17, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade php-processUpgrade php-soapUpgrade php-xmlrpcUpgrade php-mysqlUpgrade php-gdUpgrade php-pgsqlUpgrade php-cliUpgrade php-odbcUpgrade phpUpgrade php-ldapUpgrade php-pdoUpgrade php-recodeUpgrade php-commonUpgrade php-xml | Sep 28, 2020 | Jul 17, 2017 |
| Php | — | Upgrade to PHP version 7.1.7Upgrade to PHP version 7.0.21 | Jul 31, 2017 | Jul 17, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 17, 2017 |
| Ubuntu | — | Upgrade php7.0-cliUpgrade libapache2-mod-php7.0Upgrade php5-fpmUpgrade php5-cgiUpgrade php7.0-fpmUpgrade php5-cliUpgrade php7.0-cgiUpgrade libapache2-mod-php5 | Aug 10, 2017 | Jul 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub