CVE-2025-1217

Updated: 2025-05-02 01:57:01.643128

Description:

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x LOW 3.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 3.1 LOW Needs Triage 2025-04-29 04:06:33
CentOS 6 ELS php 5.3.3 3.1 LOW Ignored 2025-04-06 03:45:01
CentOS 7 ELS php 5.4.16 3.1 LOW In Testing CLSA-2025:1747740986 2025-04-18 03:57:09
CentOS 8.4 ELS php 7.4.6 3.1 LOW Released CLSA-2025:1744723009 2025-04-16 04:34:22
CentOS 8.5 ELS php 7.4.19 3.1 LOW Released CLSA-2025:1744723558 2025-04-16 04:34:23
CentOS Stream 8 ELS php 7.2.24 3.1 LOW Released CLSA-2025:1746654810 2025-05-10 05:05:24
CloudLinux 6 ELS php 5.3.3 3.1 LOW Ignored 2025-04-06 03:45:04
CloudLinux 7 ELS php 5.4.16 3.1 LOW In Testing CLSA-2025:1747742261 2025-04-18 03:57:07
Oracle Linux 6 ELS php 5.3.3 3.1 LOW Ignored 2025-04-06 03:45:03
Oracle Linux 7 ELS php 5.4.16 3.1 LOW In Testing CLSA-2025:1747690840 2025-04-18 03:57:06
Total: 14