[php-maint] Bug#881538: php7.0: CVE-2017-8923: Overflowing the length of string causes crash
carnil at debian.org
Sun Nov 12 21:33:46 UTC 2017
Tags: security upstream
Control: clone -1 -2
Control: reassign -2 src:php7.1 7.1.8-1
Control: retitle -2 php7.1: CVE-2017-8923: Overflowing the length of string causes crash
the following vulnerability was published for php7.0 and php7.1.
| The zend_string_extend function in Zend/zend_string.h in PHP through
| 7.1.5 does not prevent changes to string objects that result in a
| negative length, which allows remote attackers to cause a denial of
| service (application crash) or possibly have unspecified other impact
| by leveraging a script's use of .= with a long string.
Attached to  and  are POCs to demostrate the issue (verified on
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
More information about the pkg-php-maint