CVE-2017-5340

Source
https://cve.org/CVERecord?id=CVE-2017-5340
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5340.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-5340
Downstream
Related
Published
2017-01-11T06:59:00Z
Modified
2026-08-18T09:28:17Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.

References

Affected packages

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "7.0.0"
        },
        {
            "fixed":  "7.0.15"
        },
        {
            "introduced":  "7.1.0"
        },
        {
            "fixed":  "7.1.1"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5340.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "291942526429879441159894536430346133521",
            "length":  2665
        },
        "id":  "CVE-2017-5340-12d1fca6",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/php/php-src/commit/9abbc3cc6d0f448435ca38bef694f671bf7303d8",
        "target":  {
            "file":  "ext/gd/libgd/gd_gd2.c",
            "function":  "_gd2GetHeader"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "302809697189148475297750884608790259821",
                "25269136893474997921766866731112141155",
                "176995661728580401951558063694425109185",
                "282407999817348256037465684465485374719",
                "27203332826222208118957196914128024108",
                "327578526711602898995701292075519451415",
                "101648155586618325587449013706940504782",
                "84422741966942976358390282422869288177"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2017-5340-7501d6a6",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/php/php-src/commit/4cc0286f2f3780abc6084bcdae5dce595daa3c12",
        "target":  {
            "file":  "Zend/zend_hash.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "108479502598115741326499771321871644248",
            "length":  534
        },
        "id":  "CVE-2017-5340-7570f682",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/php/php-src/commit/4cc0286f2f3780abc6084bcdae5dce595daa3c12",
        "target":  {
            "file":  "Zend/zend_hash.c",
            "function":  "_zend_hash_init"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "268808390959611610380382661363715926383",
                "332457077737297600470842301867489262455",
                "183820387990733455444215637150999073887",
                "296117839669516092864788658433251533836"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2017-5340-a887e78f",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/php/php-src/commit/9abbc3cc6d0f448435ca38bef694f671bf7303d8",
        "target":  {
            "file":  "ext/gd/libgd/gd_gd2.c"
        }
    }
]
vanir_signatures_modified
"2026-08-18T09:28:17Z"