Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21708

Опубликовано: 17 фев. 2022
Источник: redhat
CVSS3: 9.8

Описание

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

A flaw was found in PHP. The vulnerability occurs due to the malformed php_filter_float() function and leads to a use-after-free vulnerability. This flaw allows an attacker to inject a malicious file, leading to a crash or a Segmentation fault.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Software Collectionsrh-php73-phpNot affected
Red Hat Enterprise Linux 8phpFixedRHSA-2022:762408.11.2022
Red Hat Enterprise Linux 8phpFixedRHSA-2022:762808.11.2022
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportphpFixedRHSA-2025:307620.03.2025
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicephpFixedRHSA-2025:307620.03.2025
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsphpFixedRHSA-2025:307620.03.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportphpFixedRHSA-2025:301618.03.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicephpFixedRHSA-2025:301618.03.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2055879php: Use after free due to php_filter_float() failing for ints

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 3 лет назад

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

CVSS3: 8.2
nvd
больше 3 лет назад

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

CVSS3: 8.2
debian
больше 3 лет назад

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x belo ...

suse-cvrf
больше 3 лет назад

Security update for php7

suse-cvrf
больше 3 лет назад

Security update for php7

9.8 Critical

CVSS3