CVE-2024-11233

MEDIUM

Php < 8.1.31 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

Scores

CVSS v3 4.8
EPSS 0.0073
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-122 CWE-787
Status published
Products (1)
php/php 8.1.0 - 8.1.31
Published Nov 24, 2024
Tracked Since Feb 18, 2026