Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-11236

Опубликовано: 24 нояб. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

ignored

backporting-risks-regressions
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty/esm

ignored

end of ESM support, was ignored [backporting-risks-regressions]
upstream

needed

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

esm-infra/xenial

released

7.0.33-0ubuntu0.16.04.16+esm13
focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

upstream

needed

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

released

7.2.24-0ubuntu0.18.04.17+esm7
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

upstream

needed

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

not-affected

7.4.3-4ubuntu2.26
focal

released

7.4.3-4ubuntu2.26
jammy

DNE

noble

DNE

oracular

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

released

8.1.2-1ubuntu2.20
noble

DNE

oracular

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

8.3.11-0ubuntu2
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

released

8.3.6-0ubuntu0.24.04.3
oracular

released

8.3.11-0ubuntu0.24.10.4
upstream

needs-triage

Показывать по

EPSS

Процентиль: 51%
0.00278
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
7 месяцев назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
nvd
7 месяцев назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 9.8
debian
7 месяцев назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before ...

github
7 месяцев назад

Integer overflow in the firebird and dblib quoters causing OOB writes

EPSS

Процентиль: 51%
0.00278
Низкий

9.8 Critical

CVSS3

Уязвимость CVE-2024-11236