Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2017-11628

Published: 25 July 2017

In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing code. NOTE: this is only relevant for PHP applications that accept untrusted input (instead of the system's php.ini file) for the parse_ini_string or parse_ini_file function, e.g., a web application for syntax validation of php.ini directives.

Priority

Medium

Cvss 3 Severity Score

7.8

Score breakdown

Status

Package Release Status
php5
Launchpad, Ubuntu, Debian
artful Does not exist

trusty
Released (5.5.9+dfsg-1ubuntu4.22)
upstream
Released (5.6.31)
xenial Does not exist

zesty Does not exist

Patches:
upstream: https://github.com/php/php-src/commit/5f8380d33e648964d2d5140f329cf2d4c443033c



php7.0
Launchpad, Ubuntu, Debian
artful Does not exist

trusty Does not exist

upstream
Released (7.0.21)
xenial
Released (7.0.22-0ubuntu0.16.04.1)
zesty
Released (7.0.22-0ubuntu0.17.04.1)
Patches:

upstream: https://github.com/php/php-src/commit/05255749139b3686c8a6a58ee01131ac0047465e


php7.1
Launchpad, Ubuntu, Debian
artful
Released (7.1.8-1ubuntu1)
trusty Does not exist

upstream
Released (7.1.7)
xenial Does not exist

zesty Does not exist

Patches:


upstream: https://github.com/php/php-src/commit/05255749139b3686c8a6a58ee01131ac0047465e
upstream: https://github.com/php/php-src/commit/0ba04f77379b5d277f5bd190c1542a0d91289978

Severity score breakdown

Parameter Value
Base score 7.8
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H