Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-11233

Опубликовано: 24 нояб. 2024
Источник: debian
EPSS Низкий

Описание

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.2fixed8.2.26-4package
php7.4removedpackage

Примечания

  • https://github.com/php/php-src/security/advisories/GHSA-r977-prxv-hc43

  • https://github.com/php/php-src/commit/a6c84cd7efd7eaaaefd4463412508df570d35358 (php-8.2.26)

EPSS

Процентиль: 63%
0.00458
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
12 месяцев назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

CVSS3: 4.8
redhat
12 месяцев назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

CVSS3: 4.8
nvd
12 месяцев назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

CVSS3: 8.2
msrc
11 месяцев назад

Single byte overread with convert.quoted-printable-decode filter

CVSS3: 4.8
github
12 месяцев назад

Single byte overread with convert.quoted-printable-decode filter

EPSS

Процентиль: 63%
0.00458
Низкий