In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.
References
Link Resource
https://bugs.php.net/bug.php?id=76448 Exploit Issue Tracking Patch Vendor Advisory
https://bugs.php.net/bug.php?id=76449 Exploit Issue Tracking Patch Vendor Advisory
https://bugs.php.net/bug.php?id=76450 Exploit Issue Tracking Patch Vendor Advisory
https://bugs.php.net/bug.php?id=76452 Exploit Issue Tracking Patch Vendor Advisory
https://security.gentoo.org/glsa/202209-20 Third Party Advisory
https://security.netapp.com/advisory/ntap-20211029-0006/ Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: php

Published: 2021-06-21T00:00:00

Updated: 2022-09-29T16:06:51

Reserved: 2021-01-04T00:00:00


Link: CVE-2021-21704

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-10-04T04:15:07.737

Modified: 2022-10-25T14:58:32.663


Link: CVE-2021-21704

JSON object: View

cve-icon Redhat Information

No data.