CVE-2021-21704
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others…
Does this matter?
Lower severity and a low EPSS score (1.87%). Track it; it rarely justifies an emergency change on its own.
Description
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.87% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125, CWE-190, CWE-787
- Affected
- php/php · netapp/clustered data ontap
- Source
- security@php.net
References
- https://bugs.php.net/bug.php?id=76448Exploit, Issue Tracking, Patch, Vendor Advisory
- https://bugs.php.net/bug.php?id=76449Exploit, Issue Tracking, Patch, Vendor Advisory
- https://bugs.php.net/bug.php?id=76450Exploit, Issue Tracking, Patch, Vendor Advisory
- https://bugs.php.net/bug.php?id=76452Exploit, Issue Tracking, Patch, Vendor Advisory
- https://security.gentoo.org/glsa/202209-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211029-0006/Third Party Advisory
- https://bugs.php.net/bug.php?id=76448Exploit, Issue Tracking, Patch, Vendor Advisory
- https://bugs.php.net/bug.php?id=76449Exploit, Issue Tracking, Patch, Vendor Advisory
- https://bugs.php.net/bug.php?id=76450Exploit, Issue Tracking, Patch, Vendor Advisory
- https://bugs.php.net/bug.php?id=76452Exploit, Issue Tracking, Patch, Vendor Advisory
- https://security.gentoo.org/glsa/202209-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211029-0006/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.