CERT-In Vulnerability Note
CIVN-2018-0210
Denial of Service Vulnerability in PHP
Original Issue Date:December 12, 2018
Severity Rating: HIGH
Systems Affected
- PHP versions 5.x
- PHP versions 7.x prior to 7.3.0
Overview
A vulnerability has been reported in PHP which could allow a remote attacker to cause a denial of service (DoS) condition on a targeted system.
Description
This vulnerability exists in php_imap.c file of the PHP due to a NULL pointer dereference condition. A remote attacker could exploit this vulnerability by sending a message argument with an empty string to the imap_mail function on a targeted system.
Successful exploitation of this vulnerability could cause the affected system to crash, resulting in a DoS condition.
Solution
Update to latest version
http://php.net/downloads.php
Vendor Information
PHP
https://bugs.php.net/bug.php?id=77020
References
PHP
https://bugs.php.net/bug.php?id=77020
Cisco
https://tools.cisco.com/security/center/viewAlert.x?alertId=59269
Security tracker
https://security-tracker.debian.org/tracker/CVE-2018-19935
CVE Name
CVE-2018-19935
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|