CVE-2018-19396: High severity php vulnerability
Published Nov 20, 2018
·Updated
ext/standard/varunserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.
Affected Software
1 affected component
PHP PHP>=5.0.0<=7.1.24
Event History
Nov 20, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19396?
CVE-2018-19396 is classified as a denial of service vulnerability that can cause application crashes.
2
How do I fix CVE-2018-19396?
To fix CVE-2018-19396, upgrade PHP to version 7.1.25 or later.
3
What versions of PHP are affected by CVE-2018-19396?
CVE-2018-19396 affects PHP versions from 5.0.0 up to 7.1.24.
4
What types of classes can trigger CVE-2018-19396?
CVE-2018-19396 can be triggered by unserialize calls for the com, dotnet, or variant classes.
5
Is CVE-2018-19396 specific to any operating system?
CVE-2018-19396 is related to PHP and is not specific to any particular operating system.