PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqlirealescape_string.
{
"versions": [
{
"introduced": "7.0.0"
},
{
"last_affected": "7.1.5"
},
{
"introduced": "7.4.0"
},
{
"fixed": "7.4.23"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.10"
}
]
}