CVE-2017-8923

Public on 2017-05-12
Modified on 2025-06-25
Description
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 php Not Affected
Amazon Linux 2 - Core php Not Affected
Amazon Linux 2 - Php8.2 Extra php Not Affected
Amazon Linux 1 php56 Not Affected
Amazon Linux 1 php73 No Fix Planned
Amazon Linux 2023 php8.1 Not Affected
Amazon Linux 2023 php8.2 Not Affected
Amazon Linux 2023 php8.3 Not Affected
Amazon Linux 2023 php8.4 Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD CVSSv2 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P