The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the phphandler function in sapi/apache2handler/sapiapache2.c.
{ "vanir_signatures": [ { "deprecated": false, "target": { "function": "php_handler", "file": "sapi/apache2handler/sapi_apache2.c" }, "source": "https://github.com/php/php-src/commit/23b057742e3cf199612fa8050ae86cae675e214e", "signature_type": "Function", "id": "CVE-2018-17082-68a51ab8", "signature_version": "v1", "digest": { "function_hash": "286714666792502187029051883559319256746", "length": 3972.0 } }, { "deprecated": false, "target": { "file": "sapi/apache2handler/sapi_apache2.c" }, "source": "https://github.com/php/php-src/commit/23b057742e3cf199612fa8050ae86cae675e214e", "signature_type": "Line", "id": "CVE-2018-17082-fa554c7b", "signature_version": "v1", "digest": { "line_hashes": [ "152064786699712677301454464694779181018", "29303015709440994030888303854153240592", "111547859227363177804637785761047134821", "289592337297551983891992604857677649335" ], "threshold": 0.9 } } ] }