CVE-2018-5712
Published · Updated
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 80%
exploitation probability
80%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
3 products (59 components)
Red Hat Software Collections · Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
no_fix_planned: Will not fix
Fixed
15 products (931 components)
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4) · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) · Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) · and others 10
Not affected
2 products (48 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 5
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.
Affected products
n/a · n/aReferences
http://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttps://access.redhat.com/errata/RHSA-2018:1296https://access.redhat.com/errata/RHSA-2019:2519https://bugs.php.net/bug.php?id=74782https://lists.debian.org/debian-lts-announce/2018/01/msg00025.htmlhttps://usn.ubuntu.com/3566-1/https://usn.ubuntu.com/3600-1/https://usn.ubuntu.com/3600-2/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://www.securityfocus.com/bid/102742http://www.securityfocus.com/bid/104020