CVE-2017-8923
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published May 12, 2017
Updated: Dec 27, 2024
CWE ID 787
Summary
CVE-2017-8923 is a vulnerability affecting the Zend Engine in PHP versions up to 7.1.5. The issue lies within the zend_string_extend function in zend_string.h, which fails to prevent extended string operations resulting in negative lengths. This flaw can be exploited remotely to cause a denial of service through application crashes. Additionally, it may have unspecified other impacts, potentially allowing for further exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.