Null pointer dereference in PHP - CVE-2017-9229
Published: July 6, 2017 / Updated: October 27, 2017
Vulnerability identifier: #VU7349
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9229
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition.
The weakness exists in the mbstring due to an error in handling of reg->dmin in forward_search_range(). A remote attacker can trigger SIGSEGV in left_adjust_char_head() during regular expression compilation, cause NULL pointer dereference and the application to crash.
Successful exploitation of the vulnerability results in denial of service.
The weakness exists in the mbstring due to an error in handling of reg->dmin in forward_search_range(). A remote attacker can trigger SIGSEGV in left_adjust_char_head() during regular expression compilation, cause NULL pointer dereference and the application to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
PHP
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Fedora
Red Hat Enterprise Linux for Power
Slackware Linux
EMC Integrated Data Protection Appliance
php5 (Ubuntu package)
php5 (Alpine package)
php (Alpine package)
php7 (Alpine package)
jq
php
oniguruma
Dell EMC Data Protection Search
Flex System Chassis Management Module (CMM)
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Fedora
Red Hat Enterprise Linux for Power
Slackware Linux
EMC Integrated Data Protection Appliance
php5 (Ubuntu package)
php5 (Alpine package)
php (Alpine package)
php7 (Alpine package)
jq
php
oniguruma
Dell EMC Data Protection Search
Flex System Chassis Management Module (CMM)
How to mitigate CVE-2017-9229
Update to version 7.0.21.
EMC Integrated Data Protection Appliance - update to 2.7.1
php5 (Ubuntu package) - update to 5.3.10-1ubuntu3.28
php5 (Alpine package) - update to 5.6.31-r0
php (Alpine package) - update to 5.6.31-r0
php7 (Alpine package) - update to 7.0.25-r0
Dell EMC Data Protection Search - update to 19.6.0
jq - update to 1.6-2.el7
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
php - addressed in versions 5.6.31-1.fc24, 7.0.21-1.fc25, 7.1.7-1.fc26
oniguruma - addressed in versions 5.9.6-4.fc24, 6.1.3-2.fc25, 6.1.3-3.fc25, 6.3.0-1.fc26, 6.8.2-1.el7
php5 (Ubuntu package) - update to 5.3.10-1ubuntu3.28
php5 (Alpine package) - update to 5.6.31-r0
php (Alpine package) - update to 5.6.31-r0
php7 (Alpine package) - update to 7.0.25-r0
Dell EMC Data Protection Search - update to 19.6.0
jq - update to 1.6-2.el7
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
php - addressed in versions 5.6.31-1.fc24, 7.0.21-1.fc25, 7.1.7-1.fc26
oniguruma - addressed in versions 5.9.6-4.fc24, 6.1.3-2.fc25, 6.1.3-3.fc25, 6.3.0-1.fc26, 6.8.2-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in PHP
- Slackware Linux update for php
- Amazon Linux AMI update for php56
- Ubuntu update for PHP
- Amazon Linux AMI update for php70
- Red Hat update for php
- Null pointer dereference in php5 (Alpine package)
- Null pointer dereference in php7 (Alpine package)
- Null pointer dereference in php (Alpine package)
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell EMC Data Protection Search
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Fedora 26 update for oniguruma
- Fedora 25 update for oniguruma
- Fedora 24 update for oniguruma
- Fedora 25 update for php
- Fedora 24 update for php
- Fedora 26 update for php
- Fedora 25 update for oniguruma
- Fedora EPEL 7 update for jq, oniguruma