UBUNTU-CVE-2023-3824
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-3824
UBUNTU-CVE-2023-3824
Summary:
Details: In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.
References: https://ubuntu.com/security/CVE-2023-3824, https://github.com/php/php-src/security/advisories/GHSA-jqcx-ccgc-xwhv, https://github.com/php/php-src/commit/80316123f3e9dcce8ac419bd9dd43546e2ccb5ef, https://ubuntu.com/security/notices/USN-6305-1, https://ubuntu.com/security/notices/USN-6305-2, https://www.cve.org/CVERecord?id=CVE-2023-3824
Affected packages
Package
Name: php5
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu4.29+esm16?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
