Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-8925

Опубликовано: 08 окт. 2024
Источник: debian
EPSS Низкий

Описание

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.2fixed8.2.24-1package
php7.4removedpackage

Примечания

  • Fixed in 8.3.12, 8.2.24

  • https://github.com/php/php-src/security/advisories/GHSA-9pqp-7h25-4f32

  • https://github.com/php/php-src/commit/19b49258d0c5a61398d395d8afde1123e8d161e0 (PHP-8.2.24)

  • https://blog.quarkslab.com/security-audit-of-php-src.html

EPSS

Процентиль: 21%
0.00067
Низкий

Связанные уязвимости

CVSS3: 3.1
ubuntu
10 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

CVSS3: 5.3
redhat
10 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

CVSS3: 3.1
nvd
10 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

CVSS3: 5.3
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 3.1
github
11 месяцев назад

Erroneous parsing of multipart form data

EPSS

Процентиль: 21%
0.00067
Низкий