CVE-2018-14884: Netapp Storage Automation Store
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.
Affected products
- Netapp Storage Automation Store: affected versions not specified
- PHP PHP: from 7.0.0, before 7.0.27 (fixed in 7.0.27); from 7.1.0, before 7.1.13 (fixed in 7.1.13); from 7.2.0, before 7.2.1 (fixed in 7.2.1)
Published 2018-08-03. Last modified 2026-06-17.