Red Hat Bugzilla – Bug 1629552
CVE-2018-17082 php: Cross-site scripting (XSS) flaw in Apache2 component via body of 'Transfer-Encoding: chunked' request
Last modified: 2018-10-23 09:12:05 EDT
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c. Upstream Bug: https://bugs.php.net/bug.php?id=76582 Upstream Changelog: http://php.net/ChangeLog-5.php http://php.net/ChangeLog-7.php Upstream Patch: https://github.com/php/php-src/commit/23b057742e3cf199612fa8050ae86cae675e214e
Created php tracking bugs for this issue: Affects: fedora-all [bug 1629553]