CVE-2017-12933

Priority
Description
The finish_nested_data function in ext/standard/var_unserializer.re in PHP
before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a
buffer over-read while unserializing untrusted data. Exploitation of this
issue can have an unspecified impact on the integrity of PHP.
Package
Source: php5 (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):needed
Ubuntu 14.04 LTS (Trusty Tahr):released (5.5.9+dfsg-1ubuntu4.23)
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 18.10 (Cosmic Cuttlefish):DNE
Patches:
Upstream:https://github.com/php/php-src/commit/f8c514ba6b7962a219296a837b2dbc22f749e736
Package
Upstream:released (7.1.7)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 18.10 (Cosmic Cuttlefish):DNE
Package
Upstream:released (7.0.21)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):not-affected (7.0.22-0ubuntu0.16.04.1)
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 18.10 (Cosmic Cuttlefish):DNE
More Information

Updated: 2018-10-22 16:23:09 UTC (commit b54e6a5171d67a3fa243eb9da698cc11f4eceed1)