Описание
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| php8.4 | fixed | 8.4.24-1 | package | |
| php8.2 | not-affected | package | ||
| php7.4 | not-affected | package |
Примечания
https://github.com/php/php-src/security/advisories/GHSA-x692-q9x7-8c3f
Fixed by: https://github.com/php/php-src/commit/fa18dab73f9340448c0d5c0a1d75d3fec844b358 (php-8.4.24)
Introduced with: https://github.com/php/php-src/commit/063c3c852236ecbe45ab23c0fb271b6292ce82c3 (php-8.4.3RC1)
Связанные уязвимости
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.