Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-1217

Published: March 14, 2025Last modified: March 17, 2025

Description

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.

Severity score breakdown

ParameterValue
Base score3.1
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSphp81Fixed (8.1.32-r0)
Streamphp83Fixed (8.3.18-r0)

References

ON THIS PAGE