CVE-2018-17082: Debian Linux

Medium severity, CVSS 6.1. EPSS: 4.1% chance of exploitation in the next 30 days.

The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Netapp Storage Automation Store: affected versions not specified
  • PHP PHP: before 5.6.38 (fixed in 5.6.38); from 7.0.0, before 7.0.32 (fixed in 7.0.32); from 7.1.0, before 7.1.22 (fixed in 7.1.22); from 7.2.0, before 7.2.10 (fixed in 7.2.10)

Published 2018-09-16. Last modified 2026-06-17.