cbcvebase.
CVE-2021-21702
published 2021-02-15

CVE-2021-21702: In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianphp7.4< php7.4 7.4.15-1 (bullseye)php7.4 7.4.15-1 (bullseye)
linuxlinux_kernel>= 0 < 5.4.0-214.2345.4.0-214.234
linuxlinux_kernel>= 0 < 4.4.0-267.3014.4.0-267.301
msrccbl2_php_on_cbl_mariner_2.0
oraclecommunications_diameter_signaling_router8.0.0 – 8.5.0
phpphp>= 7.3.0 < 7.3.277.3.27
phpphp>= 7.4.0 < 7.4.157.4.15
phpphp>= 8.0.0 < 8.0.28.0.2
php5php5>= 0 < 5.5.9+dfsg-1ubuntu4.29+esm145.5.9+dfsg-1ubuntu4.29+esm14
php_groupphp>= 7.3.x < 7.3.277.3.27
php_groupphp>= 7.4.x < 7.4.157.4.15
php_groupphp>= 8.0.X < 8.0.28.0.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH