See how php compares to other vendors in security performance
Fixed bug (mail() may release string with refcount==1 twice). (CVE-2019-11049)
Buffer overflow and overread in phardirread()
Fixed bug (OOB access in ldapescape). (CVE-2024-8932)
Fixed bug (Integer overflow in the dblib quoter causing OOB writes). (CVE-2024-11236)
Command injection via array-ish $command parameter of procopen()
Fixed (Stale SOAPGLOBAL(refmap) pointer with Apache Map). (CVE-2026-6722)
Argument Injection in PHP-CGI
Summary php-svg-lib fails to validate that font-family doesn't contain a PHAR url, which might leads to RCE on PHP < 8.0, and doesn't validate if external references are allowed. This might leads to bypass of restrictions or RCE on projects that are using it, if they do not strictly revalidate the fontName that is passed by php-svg-lib.
Details The Style::fromAttributes(), or the Style::parseCssStyle() should check the content of the font-family and prevents it to use a PHAR url, to avoid passing an invalid and dangerous fontName value to other libraries. The same check as done in the Style::fromStyleSheets might be reused :
if ( \arraykeyexists("font-family", $styles) && ( \strtolower(\substr($this->href, 0, 7)) === "phar://" || ($this->document->allowExternalReferences === false && \strtolower(\substr($this->href, 0, 5)) !== "data:") ) ) { unset($style["font-family"]); }
PoC
Parsing the following SVG :
<?xml version="1.0" encoding="UTF-8" standalone="no"?> <svg xmlns:svg="http://www.w3.org/2000/svg" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="200" height="200"> <text x="20" y="35" style="color:red;font-family:phar:///path/to/whatever.phar/blaklis;">My</text> </svg>
will pass the phar:///path/to/whatever.phar/blaklis as $family in SurfaceCpdf::setFont, which is then passed to the canvas selectFont as a $fontName.
Impact Libraries using this library as a dependency might be vulnerable to some bypass of restrictions, or even RCE, if they do not double check the value of the fontName that is passed by php-svg-lib
A flaw was found in php before 7.4.2. A global buffer overflow in mbflfiltconvbig5wchar function may lead to corruption of memory data.
Upstream issue:
http://bugs.php.net/79037
In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
A flaw was found in php before 7.4.2. An out of bounds read in phpstriptagsex may lead to denial of service or potentially disclosure of sensitive data.
Upstream issue:
https://bugs.php.net/79099
Fixed bug (Out-of-bounds read in iconv.c:phpiconvmimedecode() due to integer overflow) (CVE-2019-11039).
Fixed bug (heap-buffer-overflow on phpjpgget16) (CVE-2019-11040).
apachemodphp. Multiple issues were addressed by updating to PHP version 7.3.11.
Fixed bug (Heap-buffer-overflow in estrndup via exifprocessIFDTAG) (CVE-2019-11036).
apachemodphp. This issue was addressed by updating to php version 7.1.16.
Fixed bug (Use of uninitialized memory in unserialize()). (CVE-2017-5340)
Fixed bug (Heap buffer overread (READ: 1) finishnesteddata from unserialize). (CVE-2017-12933)
Fixed bug (Stack Buffer Overflow in msgfmtparsemessage). (CVE-2017-11362)
Impact The mailSend function in the default isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Patches Fixed in 5.2.18
Workarounds Filter and validate user input before passing it to internal functions.
References https://nvd.nist.gov/vuln/detail/CVE-2016-10033 Related to a follow-on issue in https://nvd.nist.gov/vuln/detail/CVE-2016-10045
For more information If you have any questions or comments about this advisory: Open a private issue in the PHPMailer project
Fixed bug GHSA-3qgc-jrrr-25jv (Bypass of CVE-2012-1823, Argument Injection in PHP-CGI). (CVE-2024-4577)
Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilterhtmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mbconvertencoding, (2) mbcheckencoding, (3) mbconvertvariables, and (4) mbparsestr functions.
Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.
Integer overflows in (1) base64encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.
PHP3 with safemode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.
php.cgi allows attackers to read any file on the system.
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
It was discovered that PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns could provoke a buffer overflow, allowing remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression.
Fixed bug (Memory corruption when loading hostile phar). (CVE-2016-10160)
Buffer overflow in the HTTP URL parsing functions in peclhttp before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable characters in a URL.