Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1217

Опубликовано: 29 мар. 2025
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.

A flaw was found in PHP. This vulnerability allows misinterpretation of HTTP response headers, potentially leading to incorrect usage of headers, MIME types, and other response attributes via incorrect parsing of folded headers in the HTTP request module.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpOut of support scope
Red Hat Enterprise Linux 8php:7.4/phpFix deferred
Red Hat Enterprise Linux 8php:8.2/phpFix deferred
Red Hat Enterprise Linux 10phpFixedRHSA-2025:748913.05.2025
Red Hat Enterprise Linux 9phpFixedRHSA-2025:426328.04.2025
Red Hat Enterprise Linux 9phpFixedRHSA-2025:741813.05.2025
Red Hat Enterprise Linux 9phpFixedRHSA-2025:743113.05.2025
Red Hat Enterprise Linux 9phpFixedRHSA-2025:743213.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2355917php: Header parser of http stream wrapper does not handle folded headers

EPSS

Процентиль: 31%
0.00113
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.

CVSS3: 3.1
nvd
3 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.

CVSS3: 3.1
msrc
3 месяца назад

Описание отсутствует

CVSS3: 3.1
debian
3 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* ...

github
3 месяца назад

Header parser of `http` stream wrapper does not handle folded headers

EPSS

Процентиль: 31%
0.00113
Низкий

3.7 Low

CVSS3

Уязвимость CVE-2025-1217