CVE-2024-8925: Erroneous parsing of multipart form data
Published Sep 26, 2024
·Updated
Erroneous parsing of multipart form data
Affected Software
14 affected componentsFixes available
PHP PHP<8.3.12
8.3.12
php-fpm PHP-FPM>=8.1.0<8.1.30
php-fpm PHP-FPM>=8.2.0<8.2.24
php-fpm PHP-FPM>=8.3.0<8.3.12
debian/php7.4<=7.4.33-1+deb11u5
7.4.33-1+deb11u8
debian/php8.2
8.2.26-1~deb12u18.2.28-1~deb12u1
PHP PHP>=8.1.0<8.1.30
PHP PHP>=8.2.0<8.2.24
PHP PHP>=8.3.0<8.3.12
Microsoft azl3 php 8.3.8-1
Microsoft cbl2 php 8.1.29-1
Microsoft azl3 php 8.3.12-1
Microsoft cbl2 php 8.1.29-1
Microsoft cbl2 php 8.1.30-1
Event History
Sep 26, 2024
CVE Published
via PHP·12:00 AM
Oct 7, 2024
Data Sourced
via Red Hat·07:52 PM
DescriptionSeverityAffected Software
Oct 8, 2024
CVE Published
via MITRE·03:35 AM
Data Sourced
via MITRE·03:35 AM
DescriptionSeverity
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Nov 1, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Feb 27, 2025
Data Sourced
via Ubuntu·09:03 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-8925?
CVE-2024-8925 has a severity rating that indicates a moderate risk due to data integrity violations.
2
How do I fix CVE-2024-8925?
To fix CVE-2024-8925, upgrade PHP to versions 8.1.30, 8.2.26 or later, or 8.3.12.
3
What is the impact of CVE-2024-8925?
The impact of CVE-2024-8925 is that improper parsing of multipart form data may result in legitimate data not being processed.
4
Which versions of PHP are affected by CVE-2024-8925?
CVE-2024-8925 affects PHP versions 8.1.0 to 8.1.29, 8.2.0 to 8.2.24, and pre-8.3.12 versions.
5
Is there a workaround for CVE-2024-8925?
There are no specific workarounds for CVE-2024-8925; upgrading to a patched version is necessary.