Описание
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 8.4.0 (включая) до 8.4.24 (исключая)Версия от 8.5.0 (включая) до 8.5.9 (исключая)
Одно из
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00522
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-787
Связанные уязвимости
CVSS3: 9.8
ubuntu
18 дней назад
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
CVSS3: 8.1
redhat
18 дней назад
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
CVSS3: 9.8
debian
18 дней назад
Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...
EPSS
Процентиль: 42%
0.00522
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-787