CVE-2017-8923

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published May 12, 2017
Updated: Dec 27, 2024
CWE ID 787

Summary

CVE-2017-8923 is a vulnerability affecting the Zend Engine in PHP versions up to 7.1.5. The issue lies within the zend_string_extend function in zend_string.h, which fails to prevent extended string operations resulting in negative lengths. This flaw can be exploited remotely to cause a denial of service through application crashes. Additionally, it may have unspecified other impacts, potentially allowing for further exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share