Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-8925

Опубликовано: 08 окт. 2024
Источник: debian
EPSS Низкий

Описание

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.2fixed8.2.24-1package
php7.4removedpackage

Примечания

  • Fixed in 8.3.12, 8.2.24

  • https://github.com/php/php-src/security/advisories/GHSA-9pqp-7h25-4f32

  • https://github.com/php/php-src/commit/19b49258d0c5a61398d395d8afde1123e8d161e0 (PHP-8.2.24)

  • https://blog.quarkslab.com/security-audit-of-php-src.html

EPSS

Процентиль: 82%
0.01777
Низкий

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 1 года назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

CVSS3: 5.3
redhat
больше 1 года назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

CVSS3: 3.1
nvd
больше 1 года назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

CVSS3: 5.3
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 3.1
github
больше 1 года назад

Erroneous parsing of multipart form data

EPSS

Процентиль: 82%
0.01777
Низкий