CVE-2018-19935
07.12.2018, 09:29
ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 5.6.0 ≤ 𝑥 < 5.6.39 |
php | php | 7.0.0 ≤ 𝑥 < 7.0.33 |
php | php | 7.1.0 ≤ 𝑥 < 7.1.26 |
php | php | 7.2.0 ≤ 𝑥 < 7.2.14 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
php-imap |
| ||||||||
php5 |
| ||||||||
php7.0 |
| ||||||||
php7.2 |
| ||||||||
php7.3 |
|
Common Weakness Enumeration
References