CVE-2024-11233: Single byte overread with convert.quoted-printable-decode filter
Fixed bug (Single byte overread with convert.quoted-printable-decode filter). (CVE-2024-11233)
Other sources
In PHP versions 8.1. before 8.1.31, 8.2. before 8.2.26, 8.3. before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PHPto a version that resolves this vulnerability.Fixed in 8.1.31 - Upgrade
Upgrade
debian/php7.4to a version that resolves this vulnerability.Fixed in 7.4.33-1+deb11u8 - Upgrade
Upgrade
debian/php8.2to a version that resolves this vulnerability.Fixed in 8.2.26-1~deb12u1Fixed in 8.2.28-1~deb12u1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.1.31-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.3.14-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.1.31 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.2.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.3.14
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11233?
CVE-2024-11233 is considered a moderate severity vulnerability due to the potential for buffer overread in specific versions of PHP.
How do I fix CVE-2024-11233?
To fix CVE-2024-11233, upgrade PHP to version 8.1.31, 8.2.26, or 8.3.14 or later.
Which PHP versions are affected by CVE-2024-11233?
CVE-2024-11233 affects PHP versions 8.1.0 to 8.1.30, 8.2.0 to 8.2.25, and 8.3.0 to 8.3.13.
What are the implications of CVE-2024-11233?
The implications of CVE-2024-11233 may include potential data exposure due to buffer overread vulnerabilities.
Is CVE-2024-11233 applicable to PHP installations on Debian?
Yes, CVE-2024-11233 is applicable to specific PHP packages on Debian, particularly versions prior to the remedied releases.