PT-2023-5957 · Php+10 · Php+10

Niels Dossche

+1

·

Published

2023-08-03

·

Updated

2025-09-29

·

CVE-2023-3824

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions 8.0.* before 8.0.30 PHP versions 8.1.* before 8.1.22 PHP versions 8.2.* before 8.2.8
Description The issue is caused by insufficient length checking when loading phar files, leading to a stack buffer overflow, which can result in memory corruption or remote code execution (RCE). This vulnerability was reportedly exploited by law enforcement agencies in Operation Cronos to compromise the LockBit ransomware group's infrastructure. The group claims that the vulnerability, specifically in PHP version 8.1.2, was used to gain access to their servers. It is estimated that over 2000 individuals and organizations have been affected by LockBit, with the group demanding over $91 million in ransom from American organizations alone. The vulnerability allows for RCE, which can enable attackers to execute arbitrary code on the affected system.
Recommendations For PHP versions 8.0.* before 8.0.30, update to version 8.0.30 or later. For PHP versions 8.1.* before 8.1.22, update to version 8.1.22 or later. For PHP versions 8.2.* before 8.2.8, update to version 8.2.8 or later. As a temporary workaround, consider disabling the phar functionality until a patch is available. Restrict access to phar files to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2023:5926
ALSA-2023:5927
ALSA-2023_5926
ALSA-2023_5927
ALSA-2024:0387
ALSA-2024:10952
ALSA-2024_0387
ALSA-2024_10949
ALSA-2024_10950
ALSA-2024_10951
ALSA-2024_10952
ALSA-2025_16880
ALT-PU-2023-5708
ALT-PU-2023-5713
ALT-PU-2023-5714
ALT-PU-2023-5911
ALT-PU-2023-7019
ALT-PU-2023-7021
AZL-27943
AZL-63070
BDU:2023-06657
BIT-LIBPHP-2023-3824
BIT-PHP-2023-3824
BIT-PHP-MIN-2023-3824
CESA-2023_5927
CESA-2024_10952
CVE-2023-3824
DLA-3555-1
DSA-5660-1
DSA-5661-1
ELSA-2023-5926
ELSA-2023-5927
ELSA-2024-0387
ELSA-2024-10952
GHSA-JQCX-CCGC-XWHV
INFSA-2023_5926
INFSA-2024_10952
MGASA-2023-0248
OESA-2023-1619
OESA-2023-1620
OESA-2023-1621
OESA-2023-1622
OESA-2023-1623
OPENSUSE-SU-2023_3498-1
OPENSUSE-SU-2023_3528-1
OPENSUSE-SU-2023_3541-1
OPENSUSE-SU-2024:13153-1
RHSA-2023:5926
RHSA-2023:5927
RHSA-2023_5926
RHSA-2023_5927
RHSA-2024:0387
RHSA-2024:10952
RHSA-2024_0387
RHSA-2024_10952
RLSA-2023:5926
RLSA-2023:5927
RLSA-2023_5927
RLSA-2024:0387
RLSA-2024:10952
RLSA-2024_0387
RLSA-2024_10952
SUSE-SU-2023:3445-1
SUSE-SU-2023:3498-1
SUSE-SU-2023:3528-1
SUSE-SU-2023:3541-1
SUSE-SU-2023_3445-1
SUSE-SU-2023_3498-1
SUSE-SU-2023_3528-1
SUSE-SU-2023_3541-1
USN-6305-1
USN-6305-2
USN-6305-3

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu