First published: Thu Nov 21 2024(Updated: )
Fixed bug (OOB access in ldap_escape). (CVE-2024-8932)
Credit: security@php.net security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
debian/php7.4 | <=7.4.33-1+deb11u5 | 7.4.33-1+deb11u7 |
debian/php8.2 | 8.2.26-1~deb12u1 8.2.27-1 | |
PHP | <8.1.31 | 8.1.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8932 is a high-severity vulnerability due to potential out-of-bounds writes resulting from an integer overflow.
To fix CVE-2024-8932, upgrade your PHP version to 8.1.31 or later, 8.2.26 or later, or ensure your PHP 7.4 is updated to 7.4.33-1+deb11u7.
CVE-2024-8932 affects PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, and 8.3.* before 8.3.14 on 32-bit systems.
CVE-2024-8932 primarily impacts 32-bit systems running vulnerable PHP versions.
Exploitation of CVE-2024-8932 can lead to uncontrolled long string inputs causing an integer overflow, resulting in potential out-of-bounds write vulnerabilities.