CVE-2024-8932

Published Nov 22, 2024

Last updated 2 months ago

Overview

Description
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
Source
security@php.net
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@php.net
CWE-787

Social media

Hype score
Not currently trending
  1. “PHP” proqramlaşdırma dilində kritik boşluq (CVE-2024-8932) aşkar olunub. #ETX #certaz #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/kBJsayB6tB

    @CERTAzerbaijan

    5 Dec 2024

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. “PHP” proqramlaşdırma dilində kritik boşluq (CVE-2024-8932) aşkar olunub. #ETX #certaz #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/Zv8BeAz0MI

    @CERTAzerbaijan

    5 Dec 2024

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. https://t.co/wLMke0IdKG > CVE-2024-8932 任意コードの実行の可能性ありとのこと。 - 8.1.31 - 8.2.26 - 8.3.14 未満がこの脆弱性の対象 パッチリリースされてるのでupdateしましょう

    @_engineer_jack

    1 Dec 2024

    127 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. PHP Patches Multi Flaws, Including CVE-2024-8932 (CVSS 9.8), Urges Immediate Update https://t.co/pF60uR1h02 #PHP #Vulnerability #CyberSecurity

    @S0fianeHamlaoui

    26 Nov 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. PHP Patches Multiple Vulnerabilities Including CVE-2024-8932 #PHP #CVE-2024-8932 https://t.co/a1elalD1Io

    @pravin_karthik

    26 Nov 2024

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-8932 and other: Multiple vulns in PHP, 4.8 - 9.8 rating 🔥 Five vulns in some PHP versions: OOB access, CRLF injection, DoS, etc. Search at https://t.co/hv7QKSqxTR: 👉 Link (all PHPs): https://t.co/pbAH9Q5eNX #cybersecurity #vulnerability_map #php https://t.co/n5z0UfU

    @Netlas_io

    26 Nov 2024

    366 Impressions

    0 Retweets

    8 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. 🚨PATCH NOW🚨 PHP Patches Multi Flaws: CVE-2024-8932, CVE-2024-8929, CVE-2024-11233, CVE-2024-11236, CVE-2024-11234 ZoomEye Dork👉app="PHP" 70m+ results are found on https://t.co/2EQoXN52Vx. ZoomEye Link: https://t.co/xlsTJiyx7m Refer: https://t.co/x6vnCsRUMZ If you want to…

    @zoomeye_team

    26 Nov 2024

    1044 Impressions

    2 Retweets

    8 Likes

    4 Bookmarks

    0 Replies

    1 Quote

  8. PHP Patches Multi Flaws, Including CVE-2024-8932 (CVSS 9.8), Urges Immediate Update https://t.co/eWhCMv82Qe

    @Dinosn

    26 Nov 2024

    3487 Impressions

    17 Retweets

    41 Likes

    13 Bookmarks

    0 Replies

    0 Quotes

  9. 2024年11月25日, わたし(#KUSANAGI9)がアップデートされたわ!みんなアップデートしてね! KUSANAGI 9 Module Update KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.1.31-1 This update includes support for vulnerability(CVE-2024-8932, CVE-2024-8929,...… https://t.co/UqPYXHqHFg

    @kusanagi_saya

    25 Nov 2024

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 2024年11月25日, わたし(#KUSANAGI9)がアップデートされたわ!みんなアップデートしてね! KUSANAGI 9 Module Update KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.2.26-1 This update includes support for vulnerability(CVE-2024-8932, CVE-2024-8929,...… https://t.co/A2QUre6GeA

    @kusanagi_saya

    25 Nov 2024

    62 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 2024年11月25日, わたし(#KUSANAGI9)がアップデートされたわ!みんなアップデートしてね! KUSANAGI 9 Module Update KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.3.14-1 This update includes support for vulnerability(CVE-2024-8932, CVE-2024-8929,...… https://t.co/NOnqXSXp9L

    @kusanagi_saya

    25 Nov 2024

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE: "CVE-2024-8932 Fecha de Publicación": "2024-11-22T06:03:29.764Z Nombre: "OOB access in ldap_escape" "baseScore": 9.8 CVE: "CVE-2024-41779 Fecha de Publicación": "2024-11-22T12:02:49.422Z Nombre: "IBM Engineering Systems Design Rhapsody - Model Manager", "baseScore": 9.8

    @hernanespinoza

    22 Nov 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes