Back

HIGH

php: Null pointer dereference via crafted "declare(ticks="

Published Apr 3, 2017

Description

The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classification of this as a vulnerability, stating "Please do not request CVEs for ordinary bugs. CVEs are relevant for security issues only.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 3, 2017
Updated Aug 5, 2024
Reserved Mar 2, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 22, 2017