High severity7.5NVD Advisory· Published Apr 3, 2017· Updated May 13, 2026
CVE-2017-6441
CVE-2017-6441
Description
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classification of this as a vulnerability, stating "Please do not request CVEs for ordinary bugs. CVEs are relevant for security issues only.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/php/php-src/pull/2396nvdPatch
- bugs.php.net/bug.phpnvdIssue Tracking
News mentions
0No linked articles in our index yet.