Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-4900

Опубликовано: 02 нояб. 2023
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.2not-affectedpackage
php7.4removedpackage
php7.3not-affectedpackage

Примечания

  • https://github.com/php/php-src/issues/8989

  • https://github.com/php/php-src/pull/9000

  • https://github.com/php/php-src/commit/789a37f14405e2d1a05a76c9fb4ed2d49d4580d5 (php-8.0.22RC1)

  • Introduced by: https://github.com/php/php-src/commit/82effb3fc7bcab0efcc343b3e03355f5f2f663c9 (php-7.4.0RC1)

EPSS

Процентиль: 27%
0.0009
Низкий

Связанные уязвимости

CVSS3: 6.2
ubuntu
больше 1 года назад

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

CVSS3: 6.2
redhat
почти 3 года назад

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

CVSS3: 6.2
nvd
больше 1 года назад

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

suse-cvrf
около 2 лет назад

Security update for php7

suse-cvrf
около 2 лет назад

Security update for php7

EPSS

Процентиль: 27%
0.0009
Низкий