Логотип exploitDog
bind:"CVE-2025-14177"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-14177"

Количество 15

Количество 15

ubuntu логотип

CVE-2025-14177

около 1 месяца назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-14177

около 1 месяца назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-14177

около 1 месяца назад

Information Leak of Memory in getimagesize

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-14177

около 1 месяца назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3237-qqm7-mfv7

около 2 месяцев назад

Information Leak of Memory in getimagesize

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20113-1

9 дней назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0086-1

26 дней назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0071-1

27 дней назад

Security update for php8

EPSS: Низкий
rocky логотип

RLSA-2026:1429

7 дней назад

Important: php:8.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1628

3 дня назад

ELSA-2026-1628: php security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1429

7 дней назад

ELSA-2026-1429: php:8.3 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:1412

7 дней назад

Important: php:8.2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:1409

7 дней назад

Important: php:8.2 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1412

7 дней назад

ELSA-2026-1412: php:8.2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1409

6 дней назад

ELSA-2026-1409: php:8.2 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2025-14177

Information Leak of Memory in getimagesize

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before ...

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3237-qqm7-mfv7

Information Leak of Memory in getimagesize

0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20113-1

Security update for php8

9 дней назад
suse-cvrf логотип
SUSE-SU-2026:0086-1

Security update for php8

26 дней назад
suse-cvrf логотип
SUSE-SU-2026:0071-1

Security update for php8

27 дней назад
rocky логотип
RLSA-2026:1429

Important: php:8.3 security update

7 дней назад
oracle-oval логотип
ELSA-2026-1628

ELSA-2026-1628: php security update (IMPORTANT)

3 дня назад
oracle-oval логотип
ELSA-2026-1429

ELSA-2026-1429: php:8.3 security update (IMPORTANT)

7 дней назад
rocky логотип
RLSA-2026:1412

Important: php:8.2 security update

7 дней назад
rocky логотип
RLSA-2026:1409

Important: php:8.2 security update

7 дней назад
oracle-oval логотип
ELSA-2026-1412

ELSA-2026-1412: php:8.2 security update (IMPORTANT)

7 дней назад
oracle-oval логотип
ELSA-2026-1409

ELSA-2026-1409: php:8.2 security update (IMPORTANT)

6 дней назад

Уязвимостей на страницу