Описание
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | ignored | backporting-risks-regressions |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | DNE | |
noble | DNE | |
oracular | DNE | |
trusty/esm | ignored | end of ESM support, was ignored [backporting-risks-regressions] |
upstream | needed |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra/focal | DNE | |
esm-infra/xenial | released | 7.0.33-0ubuntu0.16.04.16+esm13 |
focal | DNE | |
jammy | DNE | |
noble | DNE | |
oracular | DNE | |
upstream | needed |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra/bionic | released | 7.2.24-0ubuntu0.18.04.17+esm7 |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | DNE | |
noble | DNE | |
oracular | DNE | |
upstream | needed |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra/focal | not-affected | 7.4.3-4ubuntu2.26 |
focal | released | 7.4.3-4ubuntu2.26 |
jammy | DNE | |
noble | DNE | |
oracular | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | released | 8.1.2-1ubuntu2.20 |
noble | DNE | |
oracular | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | released | 8.3.11-0ubuntu2 |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | DNE | |
noble | released | 8.3.6-0ubuntu0.24.04.3 |
oracular | released | 8.3.11-0ubuntu0.24.10.4 |
upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before ...
Integer overflow in the firebird and dblib quoters causing OOB writes
EPSS
9.8 Critical
CVSS3