CVE-2018-17082
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in…
Does this matter?
Lower severity and a low EPSS score (4.10%). Track it; it rarely justifies an emergency change on its own.
Description
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 4.10% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- php/php · debian/debian linux · netapp/storage automation store
- Source
- cve@mitre.org
References
- http://php.net/ChangeLog-5.phpRelease Notes
- http://php.net/ChangeLog-7.phpRelease Notes
- https://access.redhat.com/errata/RHSA-2019:2519
- https://bugs.php.net/bug.php?id=76582Exploit, Issue Tracking, Vendor Advisory
- https://github.com/php/php-src/commit/23b057742e3cf199612fa8050ae86cae675e214ePatch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00020.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201812-01Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180924-0001/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4353Third Party Advisory
- https://www.tenable.com/security/tns-2019-07
- http://php.net/ChangeLog-5.phpRelease Notes
- http://php.net/ChangeLog-7.phpRelease Notes
- https://access.redhat.com/errata/RHSA-2019:2519
- https://bugs.php.net/bug.php?id=76582Exploit, Issue Tracking, Vendor Advisory
- https://github.com/php/php-src/commit/23b057742e3cf199612fa8050ae86cae675e214ePatch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00020.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201812-01Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180924-0001/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4353Third Party Advisory
- https://www.tenable.com/security/tns-2019-07
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.