CVE Vulnerabilities

CVE-2018-14884

NULL Pointer Dereference

Published: Aug 03, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
PhpPhp7.0.0 (including)7.0.27 (excluding)
PhpPhp7.1.0 (including)7.1.13 (excluding)
PhpPhp7.2.0 (including)7.2.1 (excluding)
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-php71-php-0:7.1.30-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHatrh-php71-php-0:7.1.30-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHatrh-php71-php-0:7.1.30-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatrh-php71-php-0:7.1.30-1.el7*
Php7.0Ubuntuupstream*
Php7.2Ubuntuupstream*

Potential Mitigations

References