UBUNTU-CVE-2017-8923
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-8923
UBUNTU-CVE-2017-8923
Summary:
Details: The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.
References: https://ubuntu.com/security/CVE-2017-8923, https://ubuntu.com/security/notices/USN-5300-1, https://ubuntu.com/security/notices/USN-5300-2, https://ubuntu.com/security/notices/USN-5300-3, https://www.cve.org/CVERecord?id=CVE-2017-8923
Affected packages
Package
Name: php5
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu4.29+esm16?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
