CVE-2017-12933

Priority
Low
Description
The finish_nested_data function in ext/standard/var_unserializer.re in PHP
before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a
buffer over-read while unserializing untrusted data. Exploitation of this
issue can have an unspecified impact on the integrity of PHP.
References
Bugs
Package
Source: php5 (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 17.10 (Artful Aardvark):DNE
Ubuntu 12.04 ESM (Precise Pangolin):needed
Ubuntu 14.04 LTS (Trusty Tahr):needed
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 17.04 (Zesty Zapus):DNE
Patches:
Upstream:https://github.com/php/php-src/commit/f8c514ba6b7962a219296a837b2dbc22f749e736
Package
Upstream:released (7.1.7)
Ubuntu 17.10 (Artful Aardvark):not-affected (7.1.8-1ubuntu1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 17.04 (Zesty Zapus):DNE
Package
Upstream:released (7.0.21)
Ubuntu 17.10 (Artful Aardvark):DNE
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (7.0.22-0ubuntu0.16.04.1)
Ubuntu 17.04 (Zesty Zapus):not-affected (7.0.22-0ubuntu0.17.04.1)
More Information

Updated: 2017-08-24 13:14:16 UTC (commit 13176)