CVE-2024-11236

Updated: 2025-11-10 01:21:35.423011

Description:

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x CRITICAL 9.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 9.8 CRITICAL Not Vulnerable 2025-01-14 02:42:04 not vulnerable
CentOS 6 ELS php 5.3.3 9.8 CRITICAL Not Vulnerable 2024-12-04 13:20:52
CentOS 7 ELS php 5.4.16 9.8 CRITICAL Not Vulnerable 2024-12-03 12:10:15
CentOS 8.4 ELS php 7.4.6 9.8 CRITICAL Not Vulnerable 2024-12-03 12:10:15
CentOS 8.5 ELS php 7.4.19 9.8 CRITICAL Not Vulnerable 2024-12-03 12:10:15
CentOS Stream 8 ELS php 7.2.24 9.8 CRITICAL Not Vulnerable 2024-12-03 12:10:15
CloudLinux 6 ELS php 5.3.3 9.8 CRITICAL Not Vulnerable 2024-12-04 13:20:52
CloudLinux 7 ELS php 5.4.16 9.8 CRITICAL Released 2024-12-02 09:53:03
Debian 10 ELS php 7.3 9.8 CRITICAL Released CLSA-2025:1761082274 2025-10-22 09:30:58
Oracle Linux 6 ELS php 5.3.3 9.8 CRITICAL Not Vulnerable 2024-12-04 13:20:52
Total: 14