First published: Mon Jun 21 2021(Updated: )
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.
Credit: security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
PHP PHP | <8.0.8 | 8.0.8 |
PHP PHP | >=7.3.0<7.3.29 | |
PHP PHP | >=7.4.0<7.4.21 | |
PHP PHP | >=8.0.0<8.0.8 | |
NetApp Clustered Data ONTAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-21704 is medium with a CVSS score of 5.9.
The affected software for CVE-2021-21704 is PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21, and 8.0.x below 8.0.8, as well as NetApp Clustered Data ONTAP.
A malicious database server can exploit CVE-2021-21704 by returning invalid response data that can cause crashes in various database functions.
Yes, the fix for CVE-2021-21704 is available in PHP version 8.0.8.
You can find more information about CVE-2021-21704 on the PHP website and the bug report links provided.