CVE-2017-11362: Buffer Overflow
Fixed bug (Stack Buffer Overflow in msgfmtparsemessage). (CVE-2017-11362)
Other sources
In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformatparse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact within International Components for Unicode (ICU) for C/C++ via a long first argument to the msgfmtparsemessage function.
Upstream bug:
https://bugs.php.net/bug.php?id=73473
Upstream patch:
http://git.php.net/?p=php-src.git;a=commit;h=95c4564f939c916538579ef63602a3cd31941c51
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.0.21 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.1.7 - Upgrade
Upgrade
PHPto a version that resolves this vulnerability.Fixed in 7.0.21 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 7.0.21 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 7.1.7 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Patch CVE-2017-11362
Event History
Frequently Asked Questions
What is CVE-2017-11362?
CVE-2017-11362 is a fixed bug in PHP 7.x that allows remote attackers to cause a denial of service or have other unspecified impact.
What is the severity of CVE-2017-11362?
The severity of CVE-2017-11362 is critical with a CVSS score of 9.8.
Which versions of PHP are affected by CVE-2017-11362?
PHP versions 7.0.0 to 7.0.21 and 7.1.0 to 7.1.7 are affected by CVE-2017-11362.
How do I fix CVE-2017-11362?
To fix CVE-2017-11362, update PHP to version 7.0.22 or 7.1.8 depending on your PHP version.
Where can I find more information about CVE-2017-11362?
You can find more information about CVE-2017-11362 on the following references: [Link 1](https://bugs.php.net/bug.php?id=73473), [Link 2](http://git.php.net/?p=php-src.git;a=commit;h=95c4564f939c916538579ef63602a3cd31941c51), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1475374).