CVE-2017-9227: Critical severity PHP PHP vulnerability
Add oniguruma upstream fix (CVE-2017-9224, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229)
Other sources
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod i ...
— Debian
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-9227?
CVE-2017-9227 is a vulnerability in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5, which allows a stack out-of-bounds read during regular expression searching, resulting in a denial of service or potentially more severe consequences.
How severe is CVE-2017-9227?
CVE-2017-9227 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
What software is affected by CVE-2017-9227?
CVE-2017-9227 affects Oniguruma 6.2.0, Oniguruma-mod in Ruby through 2.4.1, and mbstring in PHP through 7.1.5.
How do I fix CVE-2017-9227?
To fix CVE-2017-9227, update Oniguruma to version 6.3.0.
Where can I find more information about CVE-2017-9227?
You can find more information about CVE-2017-9227 at the following references: [Reference 1](https://github.com/kkos/oniguruma/issues/58), [Reference 2](https://github.com/kkos/oniguruma/commit/9690d3ab1f9bcd2db8cbe1fe3ee4a5da606b8814), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1466750)