In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.
2021-02-15T04:15:12.673
2024-11-21T05:48:51.847
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | php | php | < 7.3.27 | Yes |
Application | php | php | < 7.4.15 | Yes |
Application | php | php | < 8.0.2 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Application | netapp | clustered_data_ontap | - | Yes |
Application | oracle | communications_diameter_signaling_router | ≤ 8.5.0 | Yes |