REDHAT-BUG-1611898: SQL Injection
Published Aug 3, 2018
·Updated
PHP is vulnerable to an integer overflow in the mysqliapi.c:mysqlirealescapestring() function. An attacker could exploit this by performing a crafted query to cause a crash.
Upstream Bug:
https://bugs.php.net/bug.php?id=74544
Affected Software
1 affected component
The PHP Group PHP
Event History
Aug 3, 2018
Data Sourced
via Red Hat·02:34 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1611898?
The severity of REDHAT-BUG-1611898 is considered high due to an integer overflow vulnerability in PHP.
2
What version of PHP is affected by REDHAT-BUG-1611898?
All versions of PHP that include the mysqli_real_escape_string() function are potentially affected by REDHAT-BUG-1611898.
3
How do I fix REDHAT-BUG-1611898?
To fix REDHAT-BUG-1611898, upgrade to a patched version of PHP provided by your vendor.
4
Can REDHAT-BUG-1611898 be exploited remotely?
Yes, an attacker can exploit REDHAT-BUG-1611898 remotely by executing a crafted query.
5
What are the potential impacts of REDHAT-BUG-1611898?
The potential impacts of REDHAT-BUG-1611898 include application crashes and potential denial of service.