Vulnerability Description
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | >= 7.3.0, < 7.3.29 |
| Netapp | Clustered Data Ontap | - |
Related Weaknesses (CWE)
References
- https://bugs.php.net/bug.php?id=76448ExploitIssue TrackingPatch
- https://bugs.php.net/bug.php?id=76449ExploitIssue TrackingPatch
- https://bugs.php.net/bug.php?id=76450ExploitIssue TrackingPatch
- https://bugs.php.net/bug.php?id=76452ExploitIssue TrackingPatch
- https://security.gentoo.org/glsa/202209-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211029-0006/Third Party Advisory
- https://bugs.php.net/bug.php?id=76448ExploitIssue TrackingPatch
- https://bugs.php.net/bug.php?id=76449ExploitIssue TrackingPatch
- https://bugs.php.net/bug.php?id=76450ExploitIssue TrackingPatch
- https://bugs.php.net/bug.php?id=76452ExploitIssue TrackingPatch
- https://security.gentoo.org/glsa/202209-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211029-0006/Third Party Advisory
FAQ
What is CVE-2021-21704?
CVE-2021-21704 is a vulnerability with a CVSS score of 5.0 (MEDIUM). In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, s...
How severe is CVE-2021-21704?
CVE-2021-21704 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21704?
Check the references section above for vendor advisories and patch information. Affected products include: Php Php, Netapp Clustered Data Ontap.