CVE-2024-11236
Publication date 24 November 2024
Last updated 13 December 2024
Ubuntu priority
Cvss 3 Severity Score
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
Status
Package | Ubuntu Release | Status |
---|---|---|
php5 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
14.04 LTS trusty | Ignored end of ESM support, was ignored [backporting-risks-regressions] | |
php7.0 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
16.04 LTS xenial |
Fixed 7.0.33-0ubuntu0.16.04.16+esm13
|
|
php7.2 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic |
Fixed 7.2.24-0ubuntu0.18.04.17+esm7
|
|
php7.4 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal |
Fixed 7.4.3-4ubuntu2.26
|
|
php8.1 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy |
Fixed 8.1.2-1ubuntu2.20
|
|
20.04 LTS focal | Not in release | |
php8.3 | 24.10 oracular |
Fixed 8.3.11-0ubuntu0.24.10.4
|
24.04 LTS noble |
Fixed 8.3.6-0ubuntu0.24.04.3
|
|
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProNotes
sbeattie
PEAR issues should go against php-pear as of xenial
juliaphoebe
Fixing for trusty in php5 involves backporting a lot of infrastructure to define ZSTR_MAX_LEN across many files. Low confidence that this wouldn't cause regressions
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.8 · Critical |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-7153-1
- PHP vulnerability
- 12 December 2024
- USN-7157-1
- PHP vulnerabilities
- 13 December 2024
Other references
- https://www.cve.org/CVERecord?id=CVE-2024-11236
- https://github.com/php/php-src/security/advisories/GHSA-5hqh-c84r-qjcv
- https://github.com/php/php-src/commit/7742f79a8a9c20522dbf40e1dc1d4ccad71d399c (php-8.2.26)
- https://github.com/php/php-src/commit/2dbe1425c5768faea2aa7bca26081dd208c94ac8 (php-8.2.26)