Candidate: CVE-2017-11142 PublicDate: 2017-07-10 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11142 http://openwall.com/lists/oss-security/2017/07/10/6 http://php.net/ChangeLog-5.php http://php.net/ChangeLog-7.php Description: In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c. Ubuntu-Description: Notes: sbeattie> PEAR issues should go against php-pear as of xenial Bugs: https://bugs.php.net/bug.php?id=73807 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_php5: upstream_php5: released (5.6.31) precise/esm_php5: not-affected (code not present) trusty_php5: not-affected (code not present) trusty/esm_php5: not-affected (code not present) vivid/ubuntu-core_php5: DNE xenial_php5: DNE yakkety_php5: DNE zesty_php5: DNE devel_php5: DNE Patches_php7.0: upstream: https://github.com/php/php-src/commit/0f8cf3b8497dc45c010c44ed9e96518e11e19fc3 upstream: https://github.com/php/php-src/commit/a15bffd105ac28fd0dd9b596632dbf035238fda3 upstream_php7.0: released (7.0.17) precise/esm_php7.0: DNE trusty_php7.0: DNE trusty/esm_php7.0: DNE vivid/ubuntu-core_php7.0: DNE xenial_php7.0: not-affected (7.0.18-0ubuntu0.16.04.1) esm-infra/xenial_php7.0: not-affected (7.0.18-0ubuntu0.16.04.1) yakkety_php7.0: ignored (reached end-of-life) zesty_php7.0: not-affected (7.0.18-0ubuntu0.16.04.1) devel_php7.0: DNE Patches_php7.1: upstream_php7.1: released (7.1.3) precise/esm_php7.1: DNE trusty_php7.1: DNE trusty/esm_php7.1: DNE vivid/ubuntu-core_php7.1: DNE xenial_php7.1: DNE yakkety_php7.1: DNE zesty_php7.1: DNE devel_php7.1: not-affected (7.1.6-2ubuntu1)