Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-0568

Опубликовано: 16 фев. 2023
Источник: debian
EPSS Низкий

Описание

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.2fixed8.2.4-1package
php7.4removedpackage
php7.3removedpackage

Примечания

  • PHP Bug: https://bugs.php.net/bug.php?id=81746

  • Fixed in: 8.2.3

  • https://github.com/php/php-src/commit/ec10b28d64decbc54aa1e585dce580f0bd7a5953

EPSS

Процентиль: 33%
0.00128
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.

CVSS3: 7.5
redhat
почти 3 года назад

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.

CVSS3: 7.5
nvd
почти 3 года назад

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.

CVSS3: 8.1
msrc
почти 3 года назад

Array overrun in common path resolve code

CVSS3: 9.8
github
почти 3 года назад

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.

EPSS

Процентиль: 33%
0.00128
Низкий