CVE Database
/

CVE-2017-11628

Back to search

CVE-2017-11628

Published: Jul 25, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing code. NOTE: this is only relevant for PHP applications that accept untrusted input (instead of the system's php.ini file) for the parse_ini_string or parse_ini_file function, e.g., a web application for syntax validation of php.ini directives.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2018:1296
vendor-advisory
x_refsource_REDHAT
DSA-4081
vendor-advisory
x_refsource_DEBIAN
DSA-4080
vendor-advisory
x_refsource_DEBIAN
99489
vdb-entry
x_refsource_BID
GLSA-201709-21
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now