SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21704

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others…

MEDIUM 5.9EPSS 1.87%

Does this matter?

Lower severity and a low EPSS score (1.87%). Track it; it rarely justifies an emergency change on its own.

Description

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.87% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-125, CWE-190, CWE-787
Affected
php/php · netapp/clustered data ontap
Source
security@php.net

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.