CVE-2017-11144

In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the openssl extension PEM sealing code did not check the return value of the OpenSSL sealing function, which could lead to a crash of the PHP interpreter, related to an interpretation conflict for a negative number in ext/openssl/openssl.c, and an OpenSSL documentation omission.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
phpphp
𝑥
≤ 5.6.30
phpphp
7.0.0
phpphp
7.0.1
phpphp
7.0.2
phpphp
7.0.3
phpphp
7.0.4
phpphp
7.0.5
phpphp
7.0.6
phpphp
7.0.7
phpphp
7.0.8
phpphp
7.0.9
phpphp
7.0.10
phpphp
7.0.11
phpphp
7.0.12
phpphp
7.0.13
phpphp
7.0.14
phpphp
7.0.15
phpphp
7.0.16
phpphp
7.0.17
phpphp
7.0.18
phpphp
7.0.19
phpphp
7.0.20
phpphp
7.1.0
phpphp
7.1.1
phpphp
7.1.2
phpphp
7.1.3
phpphp
7.1.4
phpphp
7.1.5
phpphp
7.1.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php5
artful
dne
zesty
dne
yakkety
dne
xenial
dne
trusty
Fixed 5.5.9+dfsg-1ubuntu4.22
released
php7.0
artful
dne
zesty
Fixed 7.0.22-0ubuntu0.17.04.1
released
yakkety
ignored
xenial
Fixed 7.0.22-0ubuntu0.16.04.1
released
trusty
dne
php7.1
artful
Fixed 7.1.8-1ubuntu1
released
zesty
dne
yakkety
dne
xenial
dne
trusty
dne