PT-2024-6537 · Php+10 · Php+10
Faeris95
+1
·
Published
2019-06-02
·
Updated
2025-08-11
·
CVE-2024-9026
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
PHP versions 8.1.* before 8.1.30
PHP versions 8.2.* before 8.2.24
PHP versions 8.3.* before 8.3.12
Description:
The issue is related to errors in security settings of the PHP interpreter. Exploitation of this issue may allow a remote attacker to bypass existing security restrictions and manipulate PHP-FPM logs. When using PHP-FPM SAPI and it is configured to catch workers output, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. If PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same issue.
Recommendations:
For PHP versions 8.1.* before 8.1.30, update to version 8.1.30 or later.
For PHP versions 8.2.* before 8.2.24, update to version 8.2.24 or later.
For PHP versions 8.3.* before 8.3.12, update to version 8.3.12 or later.
As a temporary workaround, consider restricting the use of the
catch workers output configuration option until a patch is available.
Avoid using the syslog output configuration in PHP-FPM until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu