First published: Thu Jun 06 2024(Updated: )
Fixed bug GHSA-9fcc-425m-g385 (Bypass of CVE-2024-1874). (CVE-2024-5585)
Credit: security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | <8.2.20 | 8.2.20 |
PHP | <8.1.29 | 8.1.29 |
PHP | >=8.1.0<8.1.29 | |
PHP | >=8.2.0<8.2.20 | |
PHP | >=8.3.0<8.3.8 | |
Fedora | =40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5585 affects PHP versions 8.1.0 to 8.1.28, 8.2.0 to 8.2.19, and 8.3.0 to 8.3.7.
CVE-2024-5585 has not been officially assigned a severity rating, but it represents a critical command execution vulnerability.
To fix CVE-2024-5585, upgrade PHP to versions 8.1.29, 8.2.20, or 8.3.8 or later.
CVE-2024-5585 allows for a bypass of previous fixes if command names include trailing spaces when using proc_open().
There is no specific workaround for CVE-2024-5585; upgrading to a fixed PHP version is the recommended solution.