CVE-2018-19935

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
07/12/2018
Last modified:
29/08/2022

Description

ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.6.0 (including) 5.6.39 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.33 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 7.1.0 (including) 7.1.26 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.14 (excluding)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*