CVE-2025-1735

Updated: 2025-11-10 02:53:24.821328

Description:

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as invalid.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 6 ELS php 5.3.3 7.5 HIGH Ignored 2025-07-31 04:23:42 We have reasoned not to port this fix because of huge difference between the versions.
Oracle Linux 7 ELS php 5.4.16 7.5 HIGH Released CLSA-2025:1753953101 2025-08-01 01:01:10
RHEL 7 ELS php 5.4.16 7.5 HIGH Released CLSA-2025:1753963973 2025-08-01 01:01:09
TuxCare 9.6 ESU php 8.0.30 7.5 HIGH Released CLSA-2025:1764680377 2025-12-02 17:04:43
Ubuntu 16.04 ELS php 7.0.33 7.5 HIGH Released CLSA-2025:1757490210 2025-09-10 13:57:28
Ubuntu 18.04 ELS php 7.2.24-0 7.5 HIGH Released CLSA-2025:1757523038 2025-09-10 21:20:40
Ubuntu 20.04 ELS php 7.4.3 7.5 HIGH Released CLSA-2025:1758289909 2025-09-19 16:27:55
Total: 17