Error handling in PHP - #VU13920

 

Error handling in PHP - #VU13920

Published: July 19, 2018 / Updated: July 20, 2018


Vulnerability identifier: #VU13920
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-388
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to a fatal 'Illegal string offset' error when using array assignment on a string reference. A remote attacker can use an error handler that converts errors to exceptions and cause the service to hang.

Affected software

PHP

Remediation

The vulnerability is addressed in the versions 7.1.20, 7.2.8.

PHP - addressed in versions 7.1.20, 7.2.8

External References

Related Security Bulletins