Wind River Support Network

HomeDefectsLIN8-7502
Acknowledged

LIN8-7502 : Security Advisory - php - CVE-2017-12933

Created: Aug 28, 2017    Updated: May 29, 2018
Found In Version: 8.0.0.21
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

https://nvd.nist.gov/vuln/detail/CVE-2017-12933

CVEs


Live chat
Online