CVE-2017-12932

Source
https://cve.org/CVERecord?id=CVE-2017-12932
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-12932.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-12932
Downstream
Related
Published
2017-08-18T03:29:00.183Z
Modified
2026-05-07T21:09:37.669460Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array size. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

References

Affected packages

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Database specific
{
    "source": "CPE_FIELD",
    "cpe": [
        "cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.11:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.12:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.13:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.14:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.15:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.16:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.17:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.18:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.19:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.20:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.21:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.0.22:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.1.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.1.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.1.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.1.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.1.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.1.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.1.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.1.7:*:*:*:*:*:*:*",
        "cpe:2.3:a:php:php:7.1.8:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.0.0"
        },
        {
            "last_affected": "7.0.1"
        },
        {
            "last_affected": "7.0.2"
        },
        {
            "last_affected": "7.0.3"
        },
        {
            "last_affected": "7.0.4"
        },
        {
            "last_affected": "7.0.5"
        },
        {
            "last_affected": "7.0.6"
        },
        {
            "last_affected": "7.0.7"
        },
        {
            "last_affected": "7.0.8"
        },
        {
            "last_affected": "7.0.9"
        },
        {
            "last_affected": "7.0.10"
        },
        {
            "last_affected": "7.0.11"
        },
        {
            "last_affected": "7.0.12"
        },
        {
            "last_affected": "7.0.13"
        },
        {
            "last_affected": "7.0.14"
        },
        {
            "last_affected": "7.0.15"
        },
        {
            "last_affected": "7.0.16"
        },
        {
            "last_affected": "7.0.17"
        },
        {
            "last_affected": "7.0.18"
        },
        {
            "last_affected": "7.0.19"
        },
        {
            "last_affected": "7.0.20"
        },
        {
            "last_affected": "7.0.21"
        },
        {
            "last_affected": "7.0.22"
        },
        {
            "last_affected": "7.1.0"
        },
        {
            "last_affected": "7.1.1"
        },
        {
            "last_affected": "7.1.2"
        },
        {
            "last_affected": "7.1.3"
        },
        {
            "last_affected": "7.1.4"
        },
        {
            "last_affected": "7.1.5"
        },
        {
            "last_affected": "7.1.6"
        },
        {
            "last_affected": "7.1.7"
        },
        {
            "last_affected": "7.1.8"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-12932.json"