PT-2023-5269 · Php +10 · Php +10

Niels Dossche

+3

·

Published

2023-06-07

·

Updated

2025-08-11

·

CVE-2023-3247

CVSS v3.1
4.3
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

PHP versions 8.0.* through 8.0.28

PHP versions 8.1.* through 8.1.19

PHP versions 8.2.* through 8.2.6

Description:

The issue is related to the use of a random value generator with a narrower range of values than it should have when using SOAP HTTP Digest Authentication. In case of random generator failure, it could lead to a disclosure of 31 bits of uninitialized memory from the client to the server, and it also made easier to a malicious server to guess the client's nonce.

Recommendations:

For PHP versions 8.0.* through 8.0.28, update to version 8.0.29 or later.

For PHP versions 8.1.* through 8.1.19, update to version 8.1.20 or later.

For PHP versions 8.2.* through 8.2.6, update to version 8.2.7 or later.

As a temporary workaround, consider disabling the SOAP HTTP Digest Authentication until a patch is available.

Exploit

Fix

Use of Insufficiently Random Values

Unchecked Return Value

Weakness Enumeration

Related Identifiers

ALSA-2023:5926
ALSA-2023:5927
ALSA-2024:0387
ALSA-2024:10952
ALT-PU-2023-4106
ALT-PU-2023-4118
ALT-PU-2023-4125
ALT-PU-2023-4147
ALT-PU-2023-4152
ALT-PU-2023-7021
BDU:2023-05887
BIT-LIBPHP-2023-3247
BIT-PHP-2023-3247
BIT-PHP-MIN-2023-3247
CESA-2023_5927
CESA-2024_10952
CVE-2023-3247
DLA-3458-1
DSA-5424-1
DSA-5425-1
GHSA-76GG-C692-V2MW
INFSA-2023_5926
INFSA-2024_10952
MGASA-2023-0234
OESA-2023-1619
OESA-2023-1620
OESA-2023-1621
OESA-2023-1622
OESA-2023-1623
OPENSUSE-SU-2023_2980-1
OPENSUSE-SU-2024:13267-1
RHSA-2023:5926
RHSA-2023:5927
RHSA-2023_5926
RHSA-2023_5927
RHSA-2024:0387
RHSA-2024:10952
RHSA-2024_0387
RHSA-2024_10952
RLSA-2023:5926
RLSA-2023:5927
RLSA-2024:0387
RLSA-2024:10952
SUSE-SU-2023:2610-1
SUSE-SU-2023:2828-1
SUSE-SU-2023:2848-1
SUSE-SU-2023:2980-1
SUSE-SU-2023_2610-1
SUSE-SU-2023_2828-1
SUSE-SU-2023_2848-1
USN-6199-1
USN-6199-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu