The locale_accept_from_http function in ext/intl/locale/locale_methods.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly restrict calls to the ICU uloc_acceptLanguageFromHTTP function, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long argument.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | * | 5.5.37 |
Php | Php | 5.6.0 | 5.6.0 |
Php | Php | 5.6.0 | 5.6.0 |
Php | Php | 5.6.0 | 5.6.0 |
Php | Php | 5.6.0 | 5.6.0 |
Php | Php | 5.6.0 | 5.6.0 |
Php | Php | 5.6.0 | 5.6.0 |
Php | Php | 5.6.0 | 5.6.0 |
Php | Php | 5.6.0 | 5.6.0 |
Php | Php | 5.6.0 | 5.6.0 |
Php | Php | 5.6.1 | 5.6.1 |
Php | Php | 5.6.2 | 5.6.2 |
Php | Php | 5.6.3 | 5.6.3 |
Php | Php | 5.6.4 | 5.6.4 |
Php | Php | 5.6.5 | 5.6.5 |
Php | Php | 5.6.6 | 5.6.6 |
Php | Php | 5.6.7 | 5.6.7 |
Php | Php | 5.6.8 | 5.6.8 |
Php | Php | 5.6.9 | 5.6.9 |
Php | Php | 5.6.10 | 5.6.10 |
Php | Php | 5.6.11 | 5.6.11 |
Php | Php | 5.6.12 | 5.6.12 |
Php | Php | 5.6.13 | 5.6.13 |
Php | Php | 5.6.14 | 5.6.14 |
Php | Php | 5.6.15 | 5.6.15 |
Php | Php | 5.6.16 | 5.6.16 |
Php | Php | 5.6.17 | 5.6.17 |
Php | Php | 5.6.18 | 5.6.18 |
Php | Php | 5.6.19 | 5.6.19 |
Php | Php | 5.6.20 | 5.6.20 |
Php | Php | 5.6.21 | 5.6.21 |
Php | Php | 5.6.22 | 5.6.22 |
Php | Php | 5.6.23 | 5.6.23 |
Php | Php | 7.0.0 | 7.0.0 |
Php | Php | 7.0.1 | 7.0.1 |
Php | Php | 7.0.2 | 7.0.2 |
Php | Php | 7.0.3 | 7.0.3 |
Php | Php | 7.0.4 | 7.0.4 |
Php | Php | 7.0.5 | 7.0.5 |
Php | Php | 7.0.8 | 7.0.8 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-php56-0:2.3-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-php56-php-0:5.6.25-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-php56-php-pear-1:1.9.5-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-php56-0:2.3-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-php56-php-0:5.6.25-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-php56-php-pear-1:1.9.5-4.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-php56-0:2.3-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-php56-php-0:5.6.25-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-php56-php-pear-1:1.9.5-4.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | rh-php56-0:2.3-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | rh-php56-php-0:5.6.25-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | RedHat | rh-php56-php-pear-1:1.9.5-4.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-php56-0:2.3-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-php56-php-0:5.6.25-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-php56-php-pear-1:1.9.5-4.el7 | * |
Php5 | Ubuntu | precise | * |
Php5 | Ubuntu | trusty | * |
Php5 | Ubuntu | trusty/esm | * |
Php5 | Ubuntu | wily | * |
Php7.0 | Ubuntu | devel | * |
Php7.0 | Ubuntu | esm-infra/xenial | * |
Php7.0 | Ubuntu | upstream | * |
Php7.0 | Ubuntu | xenial | * |