CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
61.0%
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3,
core path resolution function allocate buffer one byte too small. When
resolving paths with lengths close to system MAXPATHLEN setting, this may
lead to the byte after the allocated buffer being overwritten with NUL
value, which might lead to unauthorized data access or modification.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 14.04 | noarch | php5 | < any | UNKNOWN |
ubuntu | 16.04 | noarch | php7.0 | < 7.0.33-0ubuntu0.16.04.16+esm5 | UNKNOWN |
ubuntu | 18.04 | noarch | php7.2 | < 7.2.24-0ubuntu0.18.04.17 | UNKNOWN |
ubuntu | 20.04 | noarch | php7.4 | < 7.4.3-4ubuntu2.18 | UNKNOWN |
ubuntu | 22.04 | noarch | php8.1 | < 8.1.2-1ubuntu2.11 | UNKNOWN |
ubuntu | 22.10 | noarch | php8.1 | < 8.1.7-1ubuntu3.3 | UNKNOWN |
ubuntu | 23.04 | noarch | php8.1 | < 8.1.12-1ubuntu4 | UNKNOWN |