Description
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subsequently results in copying a large string.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1326-1 | php5 security update |
Debian DLA |
DLA-1397-1 | php5 security update |
Debian DSA |
DSA-4240-1 | php7.0 security update |
Ubuntu USN |
USN-3600-1 | PHP vulnerabilities |
Ubuntu USN |
USN-3600-2 | PHP vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:31:04.995Z
Reserved: 2018-03-01T00:00:00.000Z
Link: CVE-2018-7584
No data.
Status : Modified
Published: 2018-03-01T19:29:00.293
Modified: 2024-11-21T04:12:25.040
Link: CVE-2018-7584
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN