Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hpqg-gp78-43q4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.34, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.34, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

EPSS

Процентиль: 92%
0.0878
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 5 лет назад

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

CVSS3: 8.8
redhat
около 5 лет назад

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

CVSS3: 7.4
nvd
около 5 лет назад

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

CVSS3: 7.4
debian
около 5 лет назад

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using ...

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость функции mb_strtolower () при использовании кодировки UTF-32LE интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 92%
0.0878
Низкий

Дефекты

CWE-787