CVE-2018-10546: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 9.8% chance of exploitation in the next 30 days.
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Netapp Storage Automation Store: affected versions not specified
- PHP PHP: before 5.6.36 (fixed in 5.6.36); from 7.0.0, before 7.0.30 (fixed in 7.0.30); from 7.1.0, before 7.1.17 (fixed in 7.1.17); from 7.2.0, before 7.2.5 (fixed in 7.2.5)
Published 2018-04-29. Last modified 2026-06-17.