github.comConfirmation
https://github.com/snowflakedb/pdo_snowflake/security/advisories/GHSA-f8q2-7fv5-cg93 CVE-2025-24792
MEDIUM
Snowflake PHP PDO Driver has a Signed-to-Unsigned Conversion Error
Record summary
CVE-2025-24792 has a selected CVSS score of 4.4 (medium).
Description
Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated a vulnerability in the Snowflake PHP PDO Driver where executing unsupported queries like PUT or GET on stages causes a signed-to-unsigned conversion error that crashes the application using the Driver. This vulnerability affects versions 0.2.0 through 3.0.3. Snowflake fixed the issue in version 3.1.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
pdo_snowflakeBrowse snowflakedb / pdo_snowflake | CVE List | >= 0.2.0, < 3.1.0 | affected |