PT-2017-4181 · Openssl+4 · Openssl+4
Liu Yang
+3
·
Published
2017-07-08
·
Updated
2018-05-04
·
CVE-2017-11144
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
PHP versions prior to 5.6.31
PHP versions 7.x prior to 7.0.21
PHP versions 7.1.x prior to 7.1.7
Description
The issue is related to the openssl extension in PHP, specifically with the PEM sealing code not checking the return value of the OpenSSL sealing function. This could lead to a crash of the PHP interpreter due to an interpretation conflict for a negative number. The problem is also associated with insufficient checking of unusual or exceptional states, which could allow a remote attacker to cause a denial of service.
Recommendations
For PHP versions prior to 5.6.31, update to version 5.6.31 or later.
For PHP versions 7.x prior to 7.0.21, update to version 7.0.21 or later.
For PHP versions 7.1.x prior to 7.1.7, update to version 7.1.7 or later.
Fix
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Openssl
Php
Suse
Ubuntu