Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-8929

Published: November 22, 2024Last modified: November 22, 2024

Description

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

Severity score breakdown

ParameterValue
Base score5.8
Attack VectorADJACENT_NETWORK
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSphp81Fixed (8.1.31-r0)
Streamphp83Fixed (8.3.14-r0)

References

ON THIS PAGE