Updated: 2024-11-22 21:18:56.573458
Description:
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subsequently results in copying a large string.
Links | NIST | CIRCL | RHEL | Ubuntu |
Severity | Score | |
---|---|---|
CVSS Version 2.x | HIGH | 7.5 |
CVSS Version 3.x | CRITICAL | 9.8 |
OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
---|---|---|---|---|---|---|---|---|
Debian 10 | php | 7.3 | 9.8 | CRITICAL | Needs Triage | 2025-04-28 18:30:50 | ||
Debian 10 | php | 7.0 | 9.8 | CRITICAL | Not Vulnerable | 2025-05-03 04:00:50 | ||
Debian 10 | php | 7.4 | 9.8 | CRITICAL | Needs Triage | 2025-04-28 18:30:51 | ||
Debian 10 | php | 8.0 | 9.8 | CRITICAL | Needs Triage | 2025-04-28 18:30:53 | ||
Debian 10 | php | 8.1 | 9.8 | CRITICAL | Needs Triage | 2025-04-28 18:30:54 | ||
Debian 10 | php | 8.2 | 9.8 | CRITICAL | Needs Triage | 2025-04-28 18:30:56 | ||
Debian 10 | php | 7.2 | 9.8 | CRITICAL | Not Vulnerable | 2025-05-03 04:00:49 | ||
Debian 10 | php | 7.1 | 9.8 | CRITICAL | Not Vulnerable | 2025-05-03 04:00:50 | ||
Debian 10 | php | 5.6 | 9.8 | CRITICAL | Not Vulnerable | 2025-05-03 04:00:50 | ||
Debian 11 | php | 7.0 | 9.8 | CRITICAL | Not Vulnerable | 2025-05-03 04:00:48 |