VDB
CVE-2017-11147
CVE-2017-11147
PUBLISHED
CVSS 9.100000381469727 CRITICAL
In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.
EPSS 4.71% · 91.5th percentile
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score
4.71%
91.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | php5 | 0, 5.5.3+dfsg-1ubuntu2, 5.5.6+dfsg-1ubuntu1 |
Timeline
- Jul 9, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Jan 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 15, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-11147 third-party-advisory
- http://openwall.com/lists/oss-security/2017/07/10/6 third-party-advisory
- http://php.net/ChangeLog-5.php third-party-advisory
- http://php.net/ChangeLog-7.php third-party-advisory
- https://ubuntu.com/security/notices/USN-3382-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-3382-2 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-11147 third-party-advisory