CVE-2017-9119
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.56% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- php/php · netapp/clustered data ontap · netapp/storage automation store
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/98596Third Party Advisory, VDB Entry
- https://bugs.php.net/bug.php?id=74593Exploit, Issue Tracking, Patch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20180112-0001/Third Party Advisory
- http://www.securityfocus.com/bid/98596Third Party Advisory, VDB Entry
- https://bugs.php.net/bug.php?id=74593Exploit, Issue Tracking, Patch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20180112-0001/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.