CVE-2023-3824: Buffer overflow and overread in phar_dir_read()
Buffer overflow and overread in phardirread()
Other sources
Fixed bug GHSA-jqcx-ccgc-xwhv (Buffer mismanagement in phardirread()). (CVE-2023-3824)
— PHP
In PHP version 8.0. before 8.0.30, 8.1. before 8.1.22, and 8.2. before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/php7.4to a version that resolves this vulnerability.Fixed in 7.4.33-1+deb11u5 - Upgrade
Upgrade
debian/php8.2to a version that resolves this vulnerability.Fixed in 8.2.20-1~deb12u1Fixed in 8.2.23-1 - Upgrade
Upgrade
PHPto a version that resolves this vulnerability.Fixed in 8.0.30 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 8.1.22 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 8.0.30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.2.8-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.1.22-1 - Upgrade
Upgrade
php/phar (phar_dir_read)to a version that resolves this vulnerability.Fixed in 8.0.30 - Upgrade
Upgrade
php/phar (phar_dir_read)to a version that resolves this vulnerability.Fixed in 8.1.22 - Upgrade
Upgrade
php/phar (phar_dir_read)to a version that resolves this vulnerability.Fixed in 8.2.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch GHSA-jqcx-ccgc-xwhv
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3824?
The severity of CVE-2023-3824 is critical.
How does CVE-2023-3824 affect PHP?
CVE-2023-3824 affects PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8.
What is the potential impact of CVE-2023-3824?
CVE-2023-3824 can lead to memory corruption or remote code execution (RCE).
How can I fix CVE-2023-3824?
To fix CVE-2023-3824, upgrade PHP to version 8.2.9 or later.
Where can I find more information about CVE-2023-3824?
You can find more information about CVE-2023-3824 at the following references: [Link 1](https://www.php.net/ChangeLog-8.php#8.2.9), [Link 2](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3824), [Link 3](https://github.com/php/php-src/security/advisories/GHSA-jqcx-ccgc-xwhv)