Stack-based buffer overflow in PHP - CVE-2018-7584

 

Stack-based buffer overflow in PHP - CVE-2018-7584

Published: March 1, 2018 / Updated: March 12, 2018


Vulnerability identifier: #VU10800
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7584
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to stack-based buffer overflow when handling malicious input. A remote attacker can send specially crafted HTTP response packets, trigger memory corruption and cause the application to crash.

Affected software

PHP
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Linux
Slackware Linux
Fedora
php (Red Hat package)
php5 (Ubuntu package)
php5 (Alpine package)
php7.0 (Ubuntu package)
php7 (Alpine package)
php7.1 (Ubuntu package)
php
Flex System Chassis Management Module (CMM)

How to mitigate CVE-2018-7584

Update to version 5.6.34, 7.0.28, 7.1.15.

php (Red Hat package) - update to 5.4.16-48.el7
php5 (Ubuntu package) - update to 5.5.9+dfsg-1ubuntu4.24
php5 (Alpine package) - update to 5.6.36-r0
php7.0 (Ubuntu package) - update to 7.0.28-0ubuntu0.16.04.1
php7 (Alpine package) - update to 7.0.28-r0
php7.1 (Ubuntu package) - update to 7.1.15-0ubuntu0.17.10.1
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
php - addressed in versions 7.1.15-1.fc26, 7.1.15-1.fc27

External References

Related Security Bulletins