HTTP: PHP http_fopen_wrapper Stack Buffer Overflow
This signature detects attempts to exploit a known vulnerability against PHP. A successful attack can result in a denial-of-service condition.
Extended Description
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subsequently results in copying a large string.
Affected Products
Debian debian_linux
References
BugTraq: 103204
CVE: CVE-2018-7584
URL: https://bugs.php.net/bug.php?id=75981 http://php.net/changelog-7.php
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Php
Debian
Canonical