CVE-2025-1220

Updated: 2025-11-10 02:47:12.000254

Description:

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 5.3 MEDIUM Released CLSA-2026:1769686676 2026-01-29 13:17:26
Alpine Linux 3.18 ELS php 8.2.16 5.3 MEDIUM Ignored 2025-09-10 13:44:37 Ignored due to low severity
CentOS 6 ELS php 5.3.3 5.3 MEDIUM Released CLSA-2025:1753780501 2025-08-09 01:43:48
CentOS 7 ELS php 5.4.16 5.3 MEDIUM Released CLSA-2025:1753780622 2025-08-09 01:43:42
CentOS 8.4 ELS php 7.4.6 5.3 MEDIUM Released CLSA-2025:1753793859 2025-07-30 01:50:16
CentOS 8.5 ELS php 7.4.19 5.3 MEDIUM Released CLSA-2025:1753798945 2025-07-30 01:50:17
CentOS Stream 8 ELS php 7.2.24 5.3 MEDIUM Released CLSA-2025:1753465703 2025-07-26 04:17:13
CloudLinux 6 ELS php 5.3.3 5.3 MEDIUM Ignored 2025-07-16 01:34:13 Out of support scope
CloudLinux 7 ELS php 5.4.16 5.3 MEDIUM Released CLSA-2025:1754043058 2025-08-16 01:18:36
Debian 10 ELS php 7.3 5.3 MEDIUM Ignored 2025-10-11 00:19:33 Ignored due to low severity
Total: 17