Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-11233

Опубликовано: 24 нояб. 2024
Источник: debian
EPSS Низкий

Описание

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.2fixed8.2.26-4package
php7.4removedpackage

Примечания

  • https://github.com/php/php-src/security/advisories/GHSA-r977-prxv-hc43

  • https://github.com/php/php-src/commit/a6c84cd7efd7eaaaefd4463412508df570d35358 (php-8.2.26)

EPSS

Процентиль: 42%
0.00197
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
7 месяцев назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

CVSS3: 4.8
redhat
7 месяцев назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

CVSS3: 4.8
nvd
7 месяцев назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

CVSS3: 8.2
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 4.8
github
7 месяцев назад

Single byte overread with convert.quoted-printable-decode filter

EPSS

Процентиль: 42%
0.00197
Низкий