php: Mishandled http_header_value in an atoi() call in http_fopen_wrapper.c
Published Aug 3, 2018
7.5
HIGHCVSS 3.0
EPSS 3.19%
Description
An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.
Affected products
No data.
No data.
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Enterprise Linux 5
php
Not affected
Red Hat Enterprise Linux 5
php53
Not affected
Red Hat Enterprise Linux 6
php
Not affected
Red Hat Enterprise Linux 7
php
Not affected
Red Hat Enterprise Linux 8
php
Not affected
Red Hat Software Collections
rh-php70-php
Not affected
Red Hat Software Collections
rh-php72-php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Enterprise Linux 5 | php | Not affected | n/a |
| Red Hat Enterprise Linux 5 | php53 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | php | Not affected | n/a |
| Red Hat Enterprise Linux 7 | php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php | Not affected | n/a |
| Red Hat Software Collections | rh-php70-php | Not affected | n/a |
| Red Hat Software Collections | rh-php72-php | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- http://php.net/ChangeLog-7.php x_refsource_CONFIRMVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:2519 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-14884 Vendor Advisory
- https://bugs.php.net/bug.php?id=75535 x_refsource_CONFIRMExploitIssue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1612362 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2018-14884
- https://security.netapp.com/advisory/ntap-20181107-0003/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-14884
| Link | Providers | Tags |
|---|---|---|
| http://php.net/ChangeLog-7.php | x_refsource_CONFIRMVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2019:2519 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2018-14884 | Vendor Advisory | |
| https://bugs.php.net/bug.php?id=75535 | x_refsource_CONFIRMExploitIssue TrackingPatchVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1612362 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-14884 | ||
| https://security.netapp.com/advisory/ntap-20181107-0003/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-14884 |
Change history (0)
No recorded changes yet.