CVE-2017-8923
12.05.2017, 20:29
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 𝑥 < 7.4.24 |
php | php | 8.0.0 ≤ 𝑥 < 8.0.11 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
php5 |
| ||||||||||||||||||||||||||||||||||||
php7.0 |
| ||||||||||||||||||||||||||||||||||||
php7.2 |
| ||||||||||||||||||||||||||||||||||||
php7.4 |
| ||||||||||||||||||||||||||||||||||||
php8.0 |
| ||||||||||||||||||||||||||||||||||||
php8.1 |
|
Common Weakness Enumeration