{"id":"CVE-2017-11628","details":"In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing code. NOTE: this is only relevant for PHP applications that accept untrusted input (instead of the system's php.ini file) for the parse_ini_string or parse_ini_file function, e.g., a web application for syntax validation of php.ini directives.","modified":"2026-08-07T14:48:45.616182Z","published":"2017-07-25T23:29:00.497Z","related":["SUSE-SU-2017:2303-1","SUSE-SU-2017:2317-1","SUSE-SU-2017:2522-1"],"references":[{"type":"WEB","url":"http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=05255749139b3686c8a6a58ee01131ac0047465e"},{"type":"WEB","url":"http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=5f8380d33e648964d2d5140f329cf2d4c443033c"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/99489"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1296"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201709-21"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20180112-0001/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4080"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4081"},{"type":"REPORT","url":"https://bugs.php.net/bug.php?id=74603"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"0"},{"last_affected":"195427c55481d9913ac9dd3fbcedf2f7c637e6de"},{"introduced":"60fffd296abce5fc071f3c173c25a2696cf683c6"},{"last_affected":"5b34dc2d52841bfab425cbb24e9111172de20ef9"}],"database_specific":{"cpe":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.11:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.12:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.13:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.14:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.15:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.16:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.17:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.18:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.19:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.20:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.2:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.3:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.5:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.6:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"5.6.30"},{"introduced":"7.0.0"},{"last_affected":"7.0.0"},{"introduced":"7.0.1"},{"last_affected":"7.0.1"},{"introduced":"7.0.2"},{"last_affected":"7.0.2"},{"introduced":"7.0.3"},{"last_affected":"7.0.3"},{"introduced":"7.0.4"},{"last_affected":"7.0.4"},{"introduced":"7.0.5"},{"last_affected":"7.0.5"},{"introduced":"7.0.6"},{"last_affected":"7.0.6"},{"introduced":"7.0.7"},{"last_affected":"7.0.7"},{"introduced":"7.0.8"},{"last_affected":"7.0.8"},{"introduced":"7.0.9"},{"last_affected":"7.0.9"},{"introduced":"7.0.10"},{"last_affected":"7.0.10"},{"introduced":"7.0.11"},{"last_affected":"7.0.11"},{"introduced":"7.0.12"},{"last_affected":"7.0.12"},{"introduced":"7.0.13"},{"last_affected":"7.0.13"},{"introduced":"7.0.14"},{"last_affected":"7.0.14"},{"introduced":"7.0.15"},{"last_affected":"7.0.15"},{"introduced":"7.0.16"},{"last_affected":"7.0.16"},{"introduced":"7.0.17"},{"last_affected":"7.0.17"},{"introduced":"7.0.18"},{"last_affected":"7.0.18"},{"introduced":"7.0.19"},{"last_affected":"7.0.19"},{"introduced":"7.0.20"},{"last_affected":"7.0.20"},{"introduced":"7.1.0"},{"last_affected":"7.1.0"},{"introduced":"7.1.1"},{"last_affected":"7.1.1"},{"introduced":"7.1.2"},{"last_affected":"7.1.2"},{"introduced":"7.1.3"},{"last_affected":"7.1.3"},{"introduced":"7.1.4"},{"last_affected":"7.1.4"},{"introduced":"7.1.5"},{"last_affected":"7.1.5"},{"introduced":"7.1.6"},{"last_affected":"7.1.6"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["7.0.0","7.0.1","7.0.10","7.0.11","7.0.12","7.0.13","7.0.14","7.0.15","7.0.16","7.0.17","7.0.18","7.0.19","7.0.2","7.0.20","7.0.3","7.0.4","7.0.5","7.0.6","7.0.7","7.0.8","7.0.9","7.1.0","7.1.1","7.1.2","7.1.3","7.1.4","7.1.5","7.1.6","php-7.1.6","php-7.1.6RC1","php-5.6.30","php-5.6.30RC1","POST_PHP7_NSAPI_REMOVAL","PRE_PHP7_NSAPI_REMOVAL","PRE_PHP7_EREG_MYSQL_REMOVALS","PRE_PHP7_REMOVALS","POST_PHP7_REMOVALS","POST_AST_MERGE","PRE_AST_MERGE","POST_64BIT_BRANCH_MERGE","PRE_64BIT_BRANCH_MERGE","POST_PHPNG_MERGE"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11628.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}