CVE-2023-0568

Updated: 2023-11-04 21:04:28.838104

Description:

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification. 


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 8.1

Status

OS name Project name Version Score Severity Status Errata Last updated
EL 6 PHP php 5.2 8.1 HIGH Released CLSA-2023:1680288552 2023-03-31 17:02:59
EL 6 PHP php 7.2 8.1 HIGH Released CLSA-2023:1680292775 2023-03-31 17:02:59
EL 6 PHP php 7.4 8.1 HIGH Released CLSA-2023:1680293974 2023-03-31 17:02:56
EL 6 PHP php 5.5 8.1 HIGH Released CLSA-2023:1680290281 2023-03-31 17:02:53
EL 6 PHP php 7.3 8.1 HIGH Released CLSA-2023:1680293384 2023-03-31 17:02:59
EL 6 PHP php 7.0 8.1 HIGH Released CLSA-2023:1680291553 2023-03-31 17:02:59
EL 6 PHP php 5.6 8.1 HIGH Released CLSA-2023:1680290916 2023-03-31 17:02:59
EL 6 PHP php 5.4 8.1 HIGH Released CLSA-2023:1680289635 2023-03-31 17:02:59
EL 6 PHP php 5.3 8.1 HIGH Released CLSA-2023:1680289050 2023-03-31 17:02:59
EL 6 PHP php 7.1 8.1 HIGH Released CLSA-2023:1680292142 2023-03-31 17:02:59
Total: 86