VDB
BDU%3A2018-00525
BDU%3A2018-00525
PUBLISHED
CVSS 7.5 HIGH
Уязвимость функции php_stream_url_wrap_http_ex интерпретатора PHP, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PHP Group, ООО «РусБИТех-Астра» | PHP, Astra Linux Special Edition (запись в едином реестре российских программ №369) |
Timeline
- Apr 12, 2018 CVE Published
- Mar 23, 2021 CVE Updated
References
- http://php.net/ChangeLog-7.php url
- http://www.securityfocus.com/bid/103204 url
- https://bugs.php.net/bug.php?id=75981 url
- https://github.com/php/php-src/commit/523f230c831d7b33353203fa34aee4e92ac12bba url
- https://lists.debian.org/debian-lts-announce/2018/03/msg00030.html url
- https://www.tenable.com/security/tns-2018-03 url
- https://usn.ubuntu.com/3600-1/ url
- https://nvd.nist.gov/vuln/detail/CVE-2018-7584 url
- https://security-tracker.debian.org/tracker/CVE-2018-7584 url