CVE-2025-1735

Updated: 2025-11-10 02:53:24.821328

Description:

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as invalid.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 7.5 HIGH Released CLSA-2025:1767000167 2025-12-29 18:19:08
Alpine Linux 3.18 ELS php 8.2.16 7.5 HIGH Released CLSA-2025:1766049917 2025-12-19 04:59:57
CentOS 6 ELS php 5.3.3 7.5 HIGH Ignored 2025-07-31 04:23:42 We have reasoned not to port this fix because of huge difference between the versions.
CentOS 7 ELS php 5.4.16 7.5 HIGH Released CLSA-2025:1753982448 2025-08-13 02:39:49
CentOS 8.4 ELS php 7.4.6 7.5 HIGH Released CLSA-2025:1753793859 2025-07-30 04:55:24
CentOS 8.5 ELS php 7.4.19 7.5 HIGH Released CLSA-2025:1753798945 2025-07-30 01:50:23
CentOS Stream 8 ELS php 7.2.24 7.5 HIGH Released CLSA-2025:1753465703 2025-07-26 04:17:35
CloudLinux 6 ELS php 5.3.3 7.5 HIGH Ignored 2025-08-16 01:18:40 wont fix
CloudLinux 7 ELS php 5.4.16 7.5 HIGH Released CLSA-2025:1754043058 2025-08-16 01:18:38
Debian 10 ELS php 7.3 7.5 HIGH Released CLSA-2025:1761577285 2025-10-28 00:36:54
Total: 17