Candidate: CVE-2017-6441 PublicDate: 2017-04-03 05:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6441 Description: ** DISPUTED ** The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classification of this as a vulnerability, stating "Please do not request CVEs for ordinary bugs. CVEs are relevant for security issues only." Ubuntu-Description: Notes: mdeslaur> disputed, not a security issue Bugs: https://bugs.php.net/bug.php?id=74146 Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_php5: upstream_php5: needs-triage precise_php5: ignored (reached end-of-life) precise/esm_php5: ignored trusty_php5: ignored trusty/esm_php5: ignored vivid/ubuntu-core_php5: DNE vivid/stable-phone-overlay_php5: DNE xenial_php5: DNE yakkety_php5: DNE zesty_php5: DNE devel_php5: DNE Patches_php7.0: upstream_php7.0: released (7.0.18) precise_php7.0: DNE precise/esm_php7.0: DNE trusty_php7.0: DNE trusty/esm_php7.0: DNE vivid/ubuntu-core_php7.0: DNE vivid/stable-phone-overlay_php7.0: DNE xenial_php7.0: ignored esm-infra/xenial_php7.0: ignored yakkety_php7.0: ignored zesty_php7.0: ignored devel_php7.0: DNE Patches_php7.1: upstream: https://github.com/php/php-src/pull/2396 upstream_php7.1: released (7.1.4) precise_php7.1: DNE precise/esm_php7.1: DNE trusty_php7.1: DNE trusty/esm_php7.1: DNE vivid/ubuntu-core_php7.1: DNE vivid/stable-phone-overlay_php7.1: DNE xenial_php7.1: DNE yakkety_php7.1: DNE zesty_php7.1: DNE devel_php7.1: not-affected (7.1.4-2ubuntu1)