В версиях PHP 8.4.* до 8.4.21 и 8.5.* до 8.5.6, когда имя кодировки, содержащее встроенный NUL-байт, передается в mb_convert_encoding() или связанные функции mbstring, код ошибочно предполагает, что когда strncasecmp() возвращает 0, это означает, что строки имеют одинаковую длину. Это может привести к выходу за пределы чтения глобальной памяти, что может привести к сбою, раскрытию информации или сбою. Затронутые функции включают mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables() и mb_detect_order(), а также настройки INI mbstring.detect_order и mbstring.http_output.
Показать оригинальное описание (EN)
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.
Характеристики атаки
Последствия
Строка CVSS v4.0
Тип уязвимости (CWE)
Уязвимые продукты 2
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Php Php
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
|
8.4.0
|
8.4.21
|
|
Php Php
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
|
8.5.0
|
8.5.6
|