PHP through is vulnerable to an out of bounds access in the php_pcre.c:php_pcre_replace_impl() function. An attacker could exploit this by calling preg_replace() with crafted arguments.
Upstream Bug:
https://bugs.php.net/bug.php?id=74604
This issue has been addressed in the following products:
Red Hat Software Collections for Red Hat Enterprise Linux 7
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
Via RHSA-2019:2519 https://access.redhat.com/errata/RHSA-2019:2519
Comment 8Product Security DevOps Team
2019-08-19 08:47:24 UTC