PT-2025-28036 · Opensuse+9 · Php8-8.4.10-1.1+11

Jihwan Kim

·

Published

2025-01-01

·

Updated

2026-02-10

·

CVE-2025-1220

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PHP versions prior to 8.1.33 PHP versions prior to 8.2.29 PHP versions prior to 8.3.23 PHP versions prior to 8.4.10 PHP 7.4 (affected versions not specified) PHP 8.2 (affected versions not specified)
Description PHP versions 8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, and 8.4.* before 8.4.10 are susceptible to a null character injection issue. Specifically, functions such as fsockopen() do not properly validate hostnames for null characters. This can cause functions like parse url() to interpret the hostname incorrectly, potentially leading to security problems if user code implements access checks before accessing resources. This could result in denial of service or server-side request forgery (SSRF).
Recommendations Upgrade to PHP version 8.1.33 or later. Upgrade to PHP version 8.2.29 or later. Upgrade to PHP version 8.3.23 or later. Upgrade to PHP version 8.4.10 or later. Upgrade your php8.2 packages to version 8.2.29-1~deb12u1 or later. Upgrade your php7.4 packages to the latest available version.

Exploit

Fix

NULL Pointer Dereference

SSRF

Weakness Enumeration

Related Identifiers

ALSA-2025:23309
ALSA-2026:1409
ALSA-2026:1412
ALSA-2026:2470
ALT-PU-2025-11047
ALT-PU-2025-9930
ALT-PU-2025-9934
ALT-PU-2025-9942
ALT-PU-2025-9948
AZL-65115
AZL-65250
BDU:2025-10414
BIT-LIBPHP-2025-1220
BIT-PHP-2025-1220
BIT-PHP-MIN-2025-1220
CVE-2025-1220
DLA-4254-1
DSA-5967-1
GHSA-3CR5-J632-F35R
MGASA-2025-0203
OESA-2025-1760
OESA-2025-1761
OESA-2025-1762
OESA-2025-1888
OESA-2025-1889
OESA-2025-1890
OPENSUSE-SU-2025:15340-1
RHSA-2025:23309
RHSA-2026:1409
RHSA-2026:1412
RHSA-2026:2470
SUSE-SU-2025:02462-1
SUSE-SU-2025:02463-1
SUSE-SU-2025:02473-1
SUSE-SU-2025:02474-1
SUSE-SU-2025_02462-1
SUSE-SU-2025_02463-1
SUSE-SU-2025_02473-1
SUSE-SU-2025_02474-1
USN-7648-1
USN-7648-2

Affected Products

Alt Linux
Almalinux
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Php7.4
Php8-8.4.10-1.1
Php8.2