In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Nov 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Php
Php php |
|
Weaknesses | CWE-190 | |
CPEs | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | |
Vendors & Products |
Php
Php php |
Tue, 26 Nov 2024 03:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Sun, 24 Nov 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Php Group
Php Group php |
|
CPEs | cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:* | |
Vendors & Products |
Php Group
Php Group php |
|
Metrics |
ssvc
|
Sun, 24 Nov 2024 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write. | |
Title | Integer overflow in the firebird and dblib quoters causing OOB writes | |
Weaknesses | CWE-787 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: php
Published: 2024-11-24T00:44:54.951Z
Updated: 2024-11-24T12:41:42.645Z
Reserved: 2024-11-15T06:27:40.425Z
Link: CVE-2024-11236
Vulnrichment
Updated: 2024-11-24T12:32:10.815Z
NVD
Status : Analyzed
Published: 2024-11-24T01:15:04.387
Modified: 2024-11-26T18:29:05.820
Link: CVE-2024-11236
Redhat