Buffer Overflow The advisory has been revoked - it doesn't affect any version of package php Open this link in a new tab


    Threat Intelligence

    EPSS 0.79% (82nd percentile)
Expand this section
NVD
8.8 high
Expand this section
SUSE
7.5 high
Expand this section
Red Hat
8.8 high

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-RHEL8-PHP-2932619
  • published 20 Jun 2022
  • disclosed 16 May 2022

Amendment

The Red Hat security team deemed this advisory irrelevant for RHEL:8.

NVD Description

Note: Versions mentioned in the description apply only to the upstream php package and not the php package as distributed by RHEL.

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.