Risk | Low |
Patch available | YES |
Number of vulnerabilities | 5 |
CVE-ID | N/A |
CWE-ID | CWE-119 CWE-284 CWE-401 CWE-20 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
PHP Universal components / Libraries / Scripting languages |
Vendor | PHP Group |
Security Bulletin
This security bulletin contains information about 5 vulnerabilities.
EUVDB-ID: #VU10347
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to imap_append HeapCorruction. A remote attacker can trigger memory corruption and cause the service to crash.
Update to version 7.2.2.
PHP: 7.1.13 - 7.1.13
CPE2.3 External linkshttp://bugs.php.net/bug.php?id=75774
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU10348
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to use of all interned strings free memory. A remote attacker can trigger memory corruption and cause the service to crash.
Update to version 7.2.2.
PHP: 7.1.12 - 7.1.12
CPE2.3 External linkshttp://bugs.php.net/bug.php?id=75579
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU10349
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to an error when calling on a connection to cockroach. A remote attacker can trigger memory corruption and cause pg_version() to crash.
Update to version 7.2.2.
PHP: 7.2.0 - 7.2.0
CPE2.3 External linkshttp://bugs.php.net/bug.php?id=75671
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU10350
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-401 - Memory leak
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to potential memory leak in internal classes' static members. A remote attacker can trigger NULL pointer dereference and cause the service to crash.
Update to version 7.2.2.
PHP: 7.2.0 - 7.2.0
CPE2.3 External linkshttp://bugs.php.net/bug.php?id=75742
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU10351
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to an error when handling malicious calls. A remote attacker can cause the fast CGI process to crash when PHP calls getenv() with a second parameter (local_only) of false.
Update to version 7.2.2.
PHP: 7.2.1 - 7.2.1
CPE2.3 External linkshttp://bugs.php.net/bug.php?id=75794
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?