Red Hat Bugzilla – Bug 1611898
CVE-2017-9120 php: Integer overflow in mysqli_api.c:mysqli_real_escape_string()
Last modified: 2018-10-25 11:43:44 EDT
PHP is vulnerable to an integer overflow in the mysqli_api.c:mysqli_real_escape_string() function. An attacker could exploit this by performing a crafted query to cause a crash. Upstream Bug: https://bugs.php.net/bug.php?id=74544
Created php tracking bugs for this issue: Affects: fedora-all [bug 1614880]
Upstream patch: https://bugs.php.net/patch-display.php?bug_id=74544&patch=bug74544.diff&revision=1500891082&download=1
Statement: This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 6 and 7 (versions 5.3.3 and 5.4.16, respectively).
Notice: this issue is not considered by upstream as a security issue, as it rely on bad local configuration (no memory limit) See: https://wiki.php.net/security