Description
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classification of this as a vulnerability, stating "Please do not request CVEs for ordinary bugs. CVEs are relevant for security issues only.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:25:49.366Z
Reserved: 2017-03-02T00:00:00.000Z
Link: CVE-2017-6441
No data.
Status : Modified
Published: 2017-04-03T05:59:00.910
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-6441
OpenCVE Enrichment
No data.
Weaknesses