Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-11233

Опубликовано: 24 нояб. 2024
Источник: debian
EPSS Низкий

Описание

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.2fixed8.2.26-4package
php7.4removedpackage

Примечания

  • https://github.com/php/php-src/security/advisories/GHSA-r977-prxv-hc43

  • https://github.com/php/php-src/commit/a6c84cd7efd7eaaaefd4463412508df570d35358 (php-8.2.26)

EPSS

Процентиль: 39%
0.00175
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 1 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

CVSS3: 4.8
redhat
около 1 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

CVSS3: 4.8
nvd
около 1 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

CVSS3: 8.2
msrc
около 1 года назад

Single byte overread with convert.quoted-printable-decode filter

CVSS3: 4.8
github
около 1 года назад

Single byte overread with convert.quoted-printable-decode filter

EPSS

Процентиль: 39%
0.00175
Низкий