USN-7153-1: PHP vulnerability
It was discovered that PHP incorrectly handled long string inputs in two database drivers. An attacker could possibly use this issue to write files in locations they would not normally have access to. (CVE-2024-11236)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7153-1?
USN-7153-1 has been classified as a medium-severity vulnerability due to its potential to allow unauthorized file writing by an attacker.
How do I fix USN-7153-1?
You can fix USN-7153-1 by upgrading to the fixed package versions, specifically version 7.2.24-0ubuntu0.18.04.17+esm7 or later for Ubuntu 18.04.
What are the affected packages by USN-7153-1?
The affected packages under USN-7153-1 include libapache2-mod-php7.2, libphp7.2-embed, php7.2, php7.2-common, and php7.2-dev among others.
What versions of Ubuntu are affected by USN-7153-1?
USN-7153-1 affects Ubuntu versions 16.04 and 18.04.
Can USN-7153-1 lead to remote code execution?
While USN-7153-1 allows file writing in unauthorized locations, it does not directly lead to remote code execution without further exploitation.