PT-2018-3783 · Php+4 · Php+4
Whitehat002
·
Published
2017-06-11
·
Updated
2024-06-15
·
CVE-2017-9120
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PHP versions 7.x through 7.1.5
Description
The issue is caused by an integer overflow in the
mysqli real escape string function, which can be exploited by remote attackers to cause a denial of service, resulting in a buffer overflow and application crash, or possibly have other unspecified impacts via a long string.Recommendations
For PHP versions 7.x through 7.1.5, consider updating to a version that fixes the integer overflow in the
mysqli real escape string function to prevent potential exploitation.
As a temporary workaround, consider restricting the input length to prevent long strings from being processed by the mysqli real escape string function until a patch is available.Exploit
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Php
Suse
Ubuntu