CVE-2018-7584: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 87.3% chance of exploitation in the next 30 days.
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subsequently results in copying a large string.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- PHP PHP: up to and including 5.6.33; from 7.0.0, before 7.0.28 (fixed in 7.0.28); from 7.1.0, up to and including 7.1.14; from 7.2.0, up to and including 7.2.2
Published 2018-03-01. Last modified 2026-06-17.