Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-1217

Опубликовано: 29 мар. 2025
Источник: debian
EPSS Низкий

Описание

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.4fixed8.4.5-1package
php8.2unfixedpackage
php7.4removedpackage

Примечания

  • https://github.com/php/php-src/security/advisories/GHSA-v8xr-gpvj-cx9g

  • Fixed by: https://github.com/php/php-src/commit/d20b4c97a9f883b62b65b82d939c5af9a2028ef1 (php-8.1.32)

EPSS

Процентиль: 31%
0.00113
Низкий

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.

CVSS3: 3.7
redhat
3 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.

CVSS3: 3.1
nvd
3 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.

CVSS3: 3.1
msrc
3 месяца назад

Описание отсутствует

github
3 месяца назад

Header parser of `http` stream wrapper does not handle folded headers

EPSS

Процентиль: 31%
0.00113
Низкий