PT-2017-4181 · Openssl+4 · Openssl+4

Liu Yang

+3

·

Published

2017-07-08

·

Updated

2018-05-04

·

CVE-2017-11144

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.6.31 PHP versions 7.x prior to 7.0.21 PHP versions 7.1.x prior to 7.1.7
Description The issue is related to the openssl extension in PHP, specifically with the PEM sealing code not checking the return value of the OpenSSL sealing function. This could lead to a crash of the PHP interpreter due to an interpretation conflict for a negative number. The problem is also associated with insufficient checking of unusual or exceptional states, which could allow a remote attacker to cause a denial of service.
Recommendations For PHP versions prior to 5.6.31, update to version 5.6.31 or later. For PHP versions 7.x prior to 7.0.21, update to version 7.0.21 or later. For PHP versions 7.1.x prior to 7.1.7, update to version 7.1.7 or later.

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1822
BDU:2022-02424
CVE-2017-11144
DLA-1034-1
DSA-4080-1
DSA-4081-1
OPENSUSE-SU-2017_2337-1
RHSA-2018:1296
SUSE-SU-2017:2303-1
SUSE-SU-2017:2317-1
SUSE-SU-2017:2522-1
USN-3382-1
USN-3382-2

Affected Products

Alt Linux
Openssl
Php
Suse
Ubuntu