First published: Tue Nov 20 2018(Updated: )
ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | >=5.0.0<=7.1.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19396 is classified as a denial of service vulnerability that can cause application crashes.
To fix CVE-2018-19396, upgrade PHP to version 7.1.25 or later.
CVE-2018-19396 affects PHP versions from 5.0.0 up to 7.1.24.
CVE-2018-19396 can be triggered by unserialize calls for the com, dotnet, or variant classes.
CVE-2018-19396 is related to PHP and is not specific to any particular operating system.