Back

HIGH

php: memcpy with negative length via crafted DNS response

Published Feb 22, 2019

Description

An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 22, 2019
Updated Aug 4, 2024
Reserved Feb 22, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 29, 2018