CVE-2017-9120
Summary
| CVE | CVE-2017-9120 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-02 15:29:00 UTC |
| Updated | 2022-07-20 16:39:00 UTC |
| Description | PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| August 2018 PHP Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| PHP :: Bug #74544 :: Integer overflow in mysqli_real_escape_string() |
MISC |
bugs.php.net |
Exploit, Issue Tracking, Patch, Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 198686 Ubuntu Security Notification for Hypertext Preprocessor (PHP) Vulnerabilities (USN-5300-2)
- 198690 Ubuntu Security Notification for Hypertext Preprocessor (PHP) Vulnerabilities (USN-5300-3)
- 672181 EulerOS Security Update for Hypertext Preprocessor (PHP) (EulerOS-SA-2022-2477)
- 752878 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:4067-1)
- 902525 Common Base Linux Mariner (CBL-Mariner) Security Update for Hypertext Preprocessor (PHP) (10143)