First published: Tue Oct 01 2024(Updated: )
It was discovered that PHP incorrectly handled parsing multipart form data. A remote attacker could possibly use this issue to inject payloads and cause PHP to ignore legitimate data. (CVE-2024-8925) It was discovered that PHP incorrectly handled the cgi.force_redirect configuration option due to environment variable collisions. In certain configurations, an attacker could possibly use this issue bypass force_redirect restrictions. (CVE-2024-8927) It was discovered that PHP-FPM incorrectly handled logging. A remote attacker could possibly use this issue to alter and inject arbitrary contents into log files. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-9026)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libapache2-mod-php8.3 | <8.3.6-0ubuntu0.24.04.2 | 8.3.6-0ubuntu0.24.04.2 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/php8.3-cgi | <8.3.6-0ubuntu0.24.04.2 | 8.3.6-0ubuntu0.24.04.2 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/php8.3-cli | <8.3.6-0ubuntu0.24.04.2 | 8.3.6-0ubuntu0.24.04.2 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/php8.3-fpm | <8.3.6-0ubuntu0.24.04.2 | 8.3.6-0ubuntu0.24.04.2 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/libapache2-mod-php8.1 | <8.1.2-1ubuntu2.19 | 8.1.2-1ubuntu2.19 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/php8.1-cgi | <8.1.2-1ubuntu2.19 | 8.1.2-1ubuntu2.19 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/php8.1-cli | <8.1.2-1ubuntu2.19 | 8.1.2-1ubuntu2.19 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/php8.1-fpm | <8.1.2-1ubuntu2.19 | 8.1.2-1ubuntu2.19 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/libapache2-mod-php7.4 | <7.4.3-4ubuntu2.24 | 7.4.3-4ubuntu2.24 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/php7.4-cgi | <7.4.3-4ubuntu2.24 | 7.4.3-4ubuntu2.24 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/php7.4-cli | <7.4.3-4ubuntu2.24 | 7.4.3-4ubuntu2.24 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/php7.4-fpm | <7.4.3-4ubuntu2.24 | 7.4.3-4ubuntu2.24 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)