Deserialization of untrusted data in PHP - CVE-2017-12933
Published: January 9, 2018 / Updated: January 11, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a buffer over-read while unserializing untrusted data in the finish_nested_data function in ext/standard/var_unserializer.re. A remote attacker can perform a denial of service attack.
Affected software
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
php5 (Ubuntu package)
php (Debian package)
How to mitigate CVE-2017-12933
php (Debian package) - update to 5.6.33+dfsg-0+deb8u1