PT-2017-4181 · Openssl+4 · Openssl+4

Liu Yang

+3

·

Publicado

2017-07-08

·

Atualizado

2018-05-04

·

CVE-2017-11144

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.6.31 PHP versions 7.x prior to 7.0.21 PHP versions 7.1.x prior to 7.1.7
Description The issue is related to the openssl extension in PHP, specifically with the PEM sealing code not checking the return value of the OpenSSL sealing function. This could lead to a crash of the PHP interpreter due to an interpretation conflict for a negative number. The problem is also associated with insufficient checking of unusual or exceptional states, which could allow a remote attacker to cause a denial of service.
Recommendations For PHP versions prior to 5.6.31, update to version 5.6.31 or later. For PHP versions 7.x prior to 7.0.21, update to version 7.0.21 or later. For PHP versions 7.1.x prior to 7.1.7, update to version 7.1.7 or later.

Correção

Improper Check for Exceptional Conditions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1822
BDU:2022-02424
CVE-2017-11144
DLA-1034-1
DSA-4080-1
DSA-4081-1
OPENSUSE-SU-2017_2337-1
RHSA-2018:1296
SUSE-SU-2017:2303-1
SUSE-SU-2017:2317-1
SUSE-SU-2017:2522-1
USN-3382-1
USN-3382-2

Produtos afetados

Alt Linux
Openssl
Php
Suse
Ubuntu