Back to Database
Status published
High
CVE-2017-11142
In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before...
Vulnerability Description
In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-11142
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/php/php-src/commit/0f8cf3b8497dc45c010c44ed9e96518e11e19fc3
- http://openwall.com/lists/oss-security/2017/07/10/6
- https://www.tenable.com/security/tns-2017-12
- https://bugs.php.net/bug.php?id=73807
- https://github.com/php/php-src/commit/a15bffd105ac28fd0dd9b596632dbf035238fda3
- http://php.net/ChangeLog-5.php
- https://security.netapp.com/advisory/ntap-20180112-0001/
- http://www.securityfocus.com/bid/99601
- https://www.debian.org/security/2018/dsa-4081
- http://php.net/ChangeLog-7.php
More from php
View All →CVE-2022-27158
pearweb < 1.32 suffers from Deserialization of Untrusted Data....
Critical
9.8
CVE-2022-27157
pearweb < 1.32 is suffers from a Weak Password Recovery...
Critical
9.8
CVE-2022-26635
PHP-Memcached v2.2.0 and below contains an improper NULL termination which...
Critical
9.8
CVE-2021-32610
In Archive_Tar before 1.4.14, symlinks can refer to targets outside...
High
7.1
CVE-2020-36193
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory...
Unknown
0
Affected Vendor
Affected Software
php
Vulnerable Versions:
0, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.12, 7.0.13, 7.0.14, 7.0.15, 7.0.16, 7.1.0, 7.1.1, 7.1.2
Timeline
Official Publish:
July 10th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.