The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/98596 | vdb entry third party advisory |
https://security.netapp.com/advisory/ntap-20180112-0001/ | third party advisory |
https://bugs.php.net/bug.php?id=74593 | issue tracking patch vendor advisory exploit |