Vulnerability Name:

CVE-2017-5340

Assigned:2017-01-11
Published:2017-01-11
Updated:2018-01-13
Summary:Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.
CVSS v3 Severity:9.8 Critical (CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.3 High (CCN CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
6.4 Medium (CCN Temporal CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-190
References:Source: BID
Type: UNKNOWN
95371

Source: SECTRACK
Type: UNKNOWN
1037659

Source: CONFIRM
Type: UNKNOWN
https://bugs.php.net/bug.php?id=73832

Source: XF
Type: UNKNOWN
php-zendhash-cve20175340-code-exec(120979)

Source: CONFIRM
Type: UNKNOWN
https://github.com/php/php-src/commit/4cc0286f2f3780abc6084bcdae5dce595daa3c12

Source: CONFIRM
Type: UNKNOWN
https://security.netapp.com/advisory/ntap-20180112-0001/

Vulnerable Configuration:Configuration 1:
  • cpe:/a:php:php:7.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.10:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.11:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.12:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.13:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.0.14:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:php:php:7.0.14:*:*:*:*:*:*:*
  • OR cpe:/a:php:php:7.1.0:*:*:*:*:*:*:*

  • Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20175340
    V
    CVE-2017-5340
    2018-01-23
    oval:com.ubuntu.precise:def:20175340000
    V
    CVE-2017-5340 on Ubuntu 12.04 LTS (precise) - medium.
    2017-01-11
    oval:com.ubuntu.trusty:def:20175340000
    V
    CVE-2017-5340 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-01-11
    oval:com.ubuntu.xenial:def:20175340000
    V
    CVE-2017-5340 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-01-11
    BACK
    php php 7.0.0
    php php 7.0.1
    php php 7.0.2
    php php 7.0.3
    php php 7.0.4
    php php 7.0.5
    php php 7.0.6
    php php 7.0.7
    php php 7.0.8
    php php 7.0.9
    php php 7.0.10
    php php 7.0.11
    php php 7.0.12
    php php 7.0.13
    php php 7.0.14