Red Hat Bugzilla – Bug 1611890
CVE-2017-9118 php: Out of bounds access in php_pcre.c:php_pcre_replace_impl()
Last modified: 2018-10-25 11:42:05 EDT
PHP through is vulnerable to an out of bounds access in the php_pcre.c:php_pcre_replace_impl() function. An attacker could exploit this by calling preg_replace() with crafted arguments. Upstream Bug: https://bugs.php.net/bug.php?id=74604
Created php tracking bugs for this issue: Affects: fedora-all [bug 1611891]
Upstream does not consider this as a security issue, per https://wiki.php.net/security as it rely on bas configuration (no memory limit)