The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecified impact on the integrity of PHP.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | * | 5.6.30 (including) |
Php | Php | 7.0.0 (including) | 7.0.0 (including) |
Php | Php | 7.0.1 (including) | 7.0.1 (including) |
Php | Php | 7.0.2 (including) | 7.0.2 (including) |
Php | Php | 7.0.3 (including) | 7.0.3 (including) |
Php | Php | 7.0.4 (including) | 7.0.4 (including) |
Php | Php | 7.0.5 (including) | 7.0.5 (including) |
Php | Php | 7.0.6 (including) | 7.0.6 (including) |
Php | Php | 7.0.7 (including) | 7.0.7 (including) |
Php | Php | 7.0.8 (including) | 7.0.8 (including) |
Php | Php | 7.0.9 (including) | 7.0.9 (including) |
Php | Php | 7.0.10 (including) | 7.0.10 (including) |
Php | Php | 7.0.11 (including) | 7.0.11 (including) |
Php | Php | 7.0.12 (including) | 7.0.12 (including) |
Php | Php | 7.0.13 (including) | 7.0.13 (including) |
Php | Php | 7.0.14 (including) | 7.0.14 (including) |
Php | Php | 7.0.15 (including) | 7.0.15 (including) |
Php | Php | 7.0.16 (including) | 7.0.16 (including) |
Php | Php | 7.0.17 (including) | 7.0.17 (including) |
Php | Php | 7.0.18 (including) | 7.0.18 (including) |
Php | Php | 7.0.19 (including) | 7.0.19 (including) |
Php | Php | 7.0.20 (including) | 7.0.20 (including) |
Php | Php | 7.1.0 (including) | 7.1.0 (including) |
Php | Php | 7.1.1 (including) | 7.1.1 (including) |
Php | Php | 7.1.2 (including) | 7.1.2 (including) |
Php | Php | 7.1.3 (including) | 7.1.3 (including) |
Php | Php | 7.1.4 (including) | 7.1.4 (including) |
Php | Php | 7.1.5 (including) | 7.1.5 (including) |
Php | Php | 7.1.6 (including) | 7.1.6 (including) |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-php70-php-0:7.0.27-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-php70-php-0:7.0.27-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-php70-php-0:7.0.27-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-php70-php-0:7.0.27-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-php70-php-0:7.0.27-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | rh-php70-php-0:7.0.27-1.el7 | * |
Php5 | Ubuntu | trusty | * |
Php7.0 | Ubuntu | upstream | * |
Php7.1 | Ubuntu | upstream | * |