CVE-2017-5340

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
11/01/2017
Last modified:
20/04/2025

Description

Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.15 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 7.1.0 (including) 7.1.1 (excluding)
cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*