Search CVE reports
21 – 27 of 27 results
The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this...
7 affected packages
php7.0, php5, php7.2, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php7.0 | Not in release | Not in release | Not in release | — |
php5 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Not affected |
php7.4 | Not in release | Not in release | Not affected | — |
php8.1 | Not in release | Not affected | Not in release | — |
php8.2 | Not in release | Not in release | Not in release | — |
php8.3 | Not affected | Not in release | Not in release | — |
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Not affected |
php7.4 | Not in release | Not in release | Not affected | — |
php8.1 | Not in release | Not affected | Not in release | — |
php8.2 | Not in release | Not in release | Not in release | Not in release |
php8.3 | Not affected | Not in release | Not in release | Not in release |
Some fixes available 6 of 7
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
6 affected packages
php5, php7.0, php7.2, php7.4, php8.1, php8.3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Fixed |
php7.4 | Not in release | Not in release | Fixed | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |
Some fixes available 5 of 7
In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??= operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Needs evaluation |
php7.4 | Not in release | Not in release | Fixed | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |
php8.4 | Not in release | Not in release | Not in release | — |
Some fixes available 5 of 7
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and “request_fulluri” option, the URI is not properly sanitized which can lead to HTTP request smuggling and...
6 affected packages
php5, php7.0, php7.2, php7.4, php8.1, php8.3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Needs evaluation |
php7.4 | Not in release | Not in release | Fixed | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |
Some fixes available 5 of 7
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead...
6 affected packages
php8.3, php5, php7.0, php7.2, php7.4, php8.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php8.3 | Fixed | Not in release | Not in release | — |
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Needs evaluation |
php7.4 | Not in release | Not in release | Fixed | — |
php8.1 | Not in release | Fixed | Not in release | — |
Some fixes available 2 of 3
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
7 affected packages
php8.1, php7.2, php7.4, php5, php7.0...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php8.1 | Not in release | Fixed | Not in release | Not in release |
php7.2 | — | Not in release | Not in release | Not affected |
php7.4 | — | Not in release | Fixed | Not in release |
php5 | — | Not in release | Not in release | Not in release |
php7.0 | — | Not in release | Not in release | Not in release |
php8.2 | Not in release | Not in release | Not in release | Not in release |
php8.3 | Not affected | Not in release | Not in release | Not in release |