PHP.dns_get_record.Out.of.Bounds.Read
Description
This indicates an attack attempt to exploit an Out Of Bounds Read vulnerability in PHP.
A remote attacker could exploit this vulnerability by sending a crafted DNS response to a vulnerable server which is running a PHP application. Successful exploitation could lead to information disclosure and possible application crash.
Affected Products
PHP Group PHP 7.1.x before 7.1.26
PHP Group PHP 7.2.x before 7.2.14
PHP Group PHP 7.3.x before 7.3.2
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor:
http://php.net/ChangeLog-7.php
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2019-06-06 | 14.627 | Severity:critical:high |
2019-04-08 | 14.588 | Default_action:pass:drop |
2019-03-28 | 14.582 |