First published: Mon Mar 20 2023(Updated: )
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
PHP PHP | ||
Redhat Software Collections | ||
All of | ||
PHP PHP | =8.1.0 | |
Redhat Linux | =9.0 | |
All of | ||
PHP PHP | =8.0.0 | |
Redhat Linux | =8.0 | |
All of | ||
PHP PHP | =7.4.0 | |
Redhat Linux | =8.0 | |
All of | ||
PHP PHP | ||
Redhat Linux | =6.0 | |
All of | ||
PHP PHP | ||
Redhat Linux | =7.0 | |
All of | ||
PHP PHP | ||
Redhat Linux | =9.0 | |
redhat/php | <8.0.22 | 8.0.22 |
ubuntu/php7.4 | <7.4.3-4ubuntu2.22 | 7.4.3-4ubuntu2.22 |
ubuntu/php8.1 | <8.1.2-1ubuntu2.17 | 8.1.2-1ubuntu2.17 |
debian/php7.4 | <=7.4.33-1+deb11u5 | |
debian/php8.2 | 8.2.20-1~deb12u1 8.2.23-1 | |
PHP PHP | <8.0.22 | |
Redhat Software Collections | ||
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-4900.
The severity of CVE-2022-4900 is medium with a CVSS score of 6.2.
The vulnerability in PHP occurs when the environment variable PHP_CLI_SERVER_WORKERS is set to a large value, leading to a heap buffer overflow.
PHP versions up to and excluding 8.0.22 are affected by CVE-2022-4900.
You can find more information about CVE-2022-4900 at the following references: [https://access.redhat.com/security/cve/CVE-2022-4900](https://access.redhat.com/security/cve/CVE-2022-4900), [https://bugzilla.redhat.com/show_bug.cgi?id=2179880](https://bugzilla.redhat.com/show_bug.cgi?id=2179880), [https://github.com/php/php-src/issues/8989](https://github.com/php/php-src/issues/8989).