CVE-2018-19935
07.12.2018, 09:29
ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.Enginsight
| Vendor | Product | Version |
|---|---|---|
| php | php | 5.6.0 ≤ 𝑥 < 5.6.39 |
| php | php | 7.0.0 ≤ 𝑥 < 7.0.33 |
| php | php | 7.1.0 ≤ 𝑥 < 7.1.26 |
| php | php | 7.2.0 ≤ 𝑥 < 7.2.14 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| php-imap |
| ||||||||
| php5 |
| ||||||||
| php7.0 |
| ||||||||
| php7.2 |
| ||||||||
| php7.3 |
|
Common Weakness Enumeration
References