Описание
The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.
A flaw was found in PHP. When processing certain conversion stream filters with line-break settings containing a null byte, the filter duplicates the string but retains the original length rather than the truncated size. An attacker who can influence filter options could exploit this out-of-bounds read, leading to information disclosure by leaking sensitive heap memory contents into the output stream.
Отчет
This vulnerability is rated as Moderate severity because exploitation requires an application to process untrusted input that controls specific stream filter configuration parameters, namely line-break character options containing null bytes. In standard Red Hat Enterprise Linux deployments, applications rarely expose filter instantiation parameters directly to unauthenticated external users. While an out-of-bounds read can leak adjacent memory data into the processed stream, it does not enable arbitrary code execution or system modification.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | php | Fix deferred | ||
| Red Hat Enterprise Linux 10 | php8.4 | Fix deferred | ||
| Red Hat Enterprise Linux 6 | php | Out of support scope | ||
| Red Hat Enterprise Linux 7 | php | Fix deferred | ||
| Red Hat Enterprise Linux 8 | php:7.4/php | Fix deferred | ||
| Red Hat Enterprise Linux 8 | php:8.2/php | Fix deferred | ||
| Red Hat Enterprise Linux 9 | php | Fix deferred | ||
| Red Hat Enterprise Linux 9 | php:8.2/php | Fix deferred | ||
| Red Hat Enterprise Linux 9 | php:8.3/php | Fix deferred | ||
| Red Hat Enterprise Linux 9 | php:8.4/php | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.
The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.
OOB read / info leak in convert.* stream filters when line-break-chars contains NUL
The convert.base64-encode, convert.quoted-printable-encode and convert ...
OOB read / info leak in convert.* stream filters when line-break-chars contains NUL
EPSS
5.9 Medium
CVSS3