In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact within International Components for Unicode (ICU) for C/C++ via a long first argument to the msgfmt_parse_message function.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Jul 17, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade php-recodeUpgrade php-xmlUpgrade php-pdoUpgrade php-ldapUpgrade php-processUpgrade php-xmlrpcUpgrade php-gdUpgrade php-cliUpgrade phpUpgrade php-odbcUpgrade php-commonUpgrade php-mysqlUpgrade php-soapUpgrade php-pgsql | Nov 3, 2020 | Jul 17, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade php-commonUpgrade php-ldapUpgrade php-pdoUpgrade phpUpgrade php-xmlUpgrade php-odbcUpgrade php-recodeUpgrade php-cliUpgrade php-mysqlUpgrade php-xmlrpcUpgrade php-gdUpgrade php-pgsqlUpgrade php-soapUpgrade php-process | Sep 28, 2020 | Jul 17, 2017 |
| Php | — | Upgrade to PHP version 7.1.7Upgrade to PHP version 7.0.21 | Jul 31, 2017 | Jul 17, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 17, 2017 |
| Ubuntu | — | Upgrade libapache2-mod-php7.0Upgrade php7.0-cliUpgrade php5-fpmUpgrade libapache2-mod-php5Upgrade php5-cliUpgrade php7.0-cgiUpgrade php7.0-fpmUpgrade php5-cgi | Aug 10, 2017 | Jul 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub