The vendor explicitly identifies these products as affected by this CVE.
- php as a component of Red Hat Enterprise Linux 6
- php-bcmath as a component of Red Hat Enterprise Linux 6
- php-cli as a component of Red Hat Enterprise Linux 6
- php-common as a component of Red Hat Enterprise Linux 6
- php-dba as a component of Red Hat Enterprise Linux 6
- php-devel as a component of Red Hat Enterprise Linux 6
- php-embedded as a component of Red Hat Enterprise Linux 6
- php-enchant as a component of Red Hat Enterprise Linux 6
- php-fpm as a component of Red Hat Enterprise Linux 6
- php-gd as a component of Red Hat Enterprise Linux 6
- php-imap as a component of Red Hat Enterprise Linux 6
- php-intl as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in PHP. A remote attacker could exploit this vulnerability by providing specially crafted inputs to the `bccomp()` function. This could lead to an out-of-bounds write, resulting in stack and heap corruption. Such memory corruption can enable arbitrary code execution, allowing the attacker to take control of the affected system.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
