Description
An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2016-7129)
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Scripting (2.6.2)
Magento Cryptographic Issues Vulnerability (CVE-2019-7860)
Oracle Database Server Incorrect Calculation of Buffer Size Vulnerability (CVE-2004-1363)