Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-4900

Опубликовано: 13 июл. 2022
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpOut of support scope
Red Hat Enterprise Linux 8php:7.4/phpFix deferred
Red Hat Enterprise Linux 9phpFix deferred
Red Hat Enterprise Linux 9php:8.1/phpFix deferred
Red Hat Software Collectionsrh-php73-phpFix deferred
Red Hat Enterprise Linux 8phpFixedRHSA-2023:084821.02.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2179880php: potential buffer overflow in php_cli_server_startup_workers

EPSS

Процентиль: 27%
0.0009
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
больше 1 года назад

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

CVSS3: 6.2
nvd
больше 1 года назад

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

CVSS3: 6.2
debian
больше 1 года назад

A vulnerability was found in PHP where setting the environment variabl ...

suse-cvrf
около 2 лет назад

Security update for php7

suse-cvrf
около 2 лет назад

Security update for php7

EPSS

Процентиль: 27%
0.0009
Низкий

6.2 Medium

CVSS3