The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Huawei Euleros 2_0_sp8 | — | Upgrade php-xmlUpgrade php-commonUpgrade phpUpgrade php-processUpgrade php-cliUpgrade php-recodeUpgrade php-odbcUpgrade php-gdUpgrade php-ldapUpgrade php-pdoUpgrade php-fpmUpgrade php-soapUpgrade php-xmlrpc | Oct 11, 2022 | May 21, 2017 |
| Php | — | Upgrade to PHP version 7.1.6 | Jun 6, 2017 | May 21, 2017 |
| Ubuntu | — | Upgrade php7.2-cliUpgrade php7.4-fpmUpgrade php7.0-cli (Ubuntu Pro)Upgrade php7.4-cliUpgrade php7.2-fpmUpgrade php7.0-cgi (Ubuntu Pro)Upgrade php7.2-cgiUpgrade php7.4-cgiUpgrade php7.0-fpm (Ubuntu Pro) | Feb 23, 2022 | May 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub