CVE-2021-21704

Description

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.138

Associated Vulnerability

VulnerabilityOS Platform
php7.3 security update(DSA-4935-1) php7.3_7.3.29-1~deb10u1_all.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.2-cgi_7.2.24-0ubuntu0.18.04.8_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.2-cgi_7.2.24-0ubuntu0.18.04.8_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.2-cli_7.2.24-0ubuntu0.18.04.8_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.2-cli_7.2.24-0ubuntu0.18.04.8_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.2-fpm_7.2.24-0ubuntu0.18.04.8_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.2-fpm_7.2.24-0ubuntu0.18.04.8_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cgi_7.4.3-4ubuntu2.5_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cgi_7.4.3-4ubuntu2.5_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cgi_7.4.9-1ubuntu1.2_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cgi_7.4.9-1ubuntu1.2_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cgi_7.4.16-1ubuntu2.1_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cgi_7.4.16-1ubuntu2.1_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cli_7.4.3-4ubuntu2.5_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cli_7.4.3-4ubuntu2.5_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cli_7.4.9-1ubuntu1.2_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cli_7.4.9-1ubuntu1.2_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cli_7.4.16-1ubuntu2.1_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-cli_7.4.16-1ubuntu2.1_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-fpm_7.4.3-4ubuntu2.5_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-fpm_7.4.3-4ubuntu2.5_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-fpm_7.4.9-1ubuntu1.2_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-fpm_7.4.9-1ubuntu1.2_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-fpm_7.4.16-1ubuntu2.1_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) php7.4-fpm_7.4.16-1ubuntu2.1_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) libapache2-mod-php7.2_7.2.24-0ubuntu0.18.04.8_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) libapache2-mod-php7.2_7.2.24-0ubuntu0.18.04.8_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) libapache2-mod-php7.4_7.4.3-4ubuntu2.5_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) libapache2-mod-php7.4_7.4.3-4ubuntu2.5_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) libapache2-mod-php7.4_7.4.9-1ubuntu1.2_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) libapache2-mod-php7.4_7.4.9-1ubuntu1.2_amd64.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) libapache2-mod-php7.4_7.4.16-1ubuntu2.1_i386.debLinux
HTML-embedded scripting language interpreter (USN-5006-1) libapache2-mod-php7.4_7.4.16-1ubuntu2.1_amd64.debLinux
SUSE-SU-2021:2637-1(SUSE Linux Enterprise Module for Web Scripting 15-SP3 ) php7-7.4.6-3.22.1.x86_64.rpmLinux
SUSE-SU-2021:2637-1(SUSE Linux Enterprise Module for Web Scripting 15-SP3 ) php7-debuginfo-7.4.6-3.22.1.x86_64.rpmLinux
Out-of-bounds Write Vulnerability (CVE-2021-21704)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234