PT-2025-52599 · Php+6 · Php+6
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PHP versions 8.1.0 through 8.1.33
PHP versions 8.2.0 through 8.2.29
PHP versions 8.3.0 through 8.3.28
PHP versions 8.4.0 through 8.4.15
PHP versions 8.5.0
Description
When using the PDO PostgreSQL driver with
PDO::ATTR EMULATE PREPARES enabled, an invalid character sequence in a prepared statement parameter may cause the PQescapeStringConn() function to return NULL. This leads to a null pointer dereference within the pdo parse params() function, which can result in a segmentation fault and cause a denial of service by crashing the target server.Recommendations
Update to version 8.1.34 or later.
Update to version 8.2.30 or later.
Update to version 8.3.29 or later.
Update to version 8.4.16 or later.
Update to version 8.5.1 or later.
As a temporary mitigation, disable the
PDO::ATTR EMULATE PREPARES setting when using the PDO PostgreSQL driver.Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Php
Red Os
Rocky Linux
Ubuntu