Php · Php · CVE-2024-11233
Name of the Vulnerable Software and Affected Versions:
PHP versions 8.1.* before 8.1.31
PHP versions 8.2.* before 8.2.26
PHP versions 8.3.* before 8.3.14
Description:
The issue is related to an error in the `convert.quoted-printable-decode` filter, which can lead to a buffer overread by one byte. This can cause crashes or disclose the content of other memory areas in certain circumstances. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations:
For PHP versions 8.1.* before 8.1.31, update to version 8.1.31 or later.
For PHP versions 8.2.* before 8.2.26, update to version 8.2.26 or later.
For PHP versions 8.3.* before 8.3.14, update to version 8.3.14 or later.