An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.
2018-08-03T13:29:00.317
2024-11-21T03:50:00.603
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | php | php | < 7.0.27 | Yes |
| Application | php | php | < 7.1.13 | Yes |
| Application | php | php | < 7.2.1 | Yes |
| Application | netapp | storage_automation_store | - | Yes |