CVE-2024-8926
08.10.2024, 04:15
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12,when using a certain non-standard configurations of Windows codepages, the fixes for CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3 may still be bypassed and the same command injection related to Windows "Best Fit" codepage behavior can be achieved. Thismay allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
Vendor | Product | Version |
---|---|---|
php | php | 8.1.30 < 𝑥 < 8.1.30 |
php | php | 8.2.24 < 𝑥 < 8.2.24 |
php | php | 8.3.12 < 𝑥 < 8.3.12 |
php-fpm | php-fpm | 8.1.0 ≤ 𝑥 < 8.1.30 |
php-fpm | php-fpm | 8.2.0 ≤ 𝑥 < 8.2.24 |
php-fpm | php-fpm | 8.3.0 ≤ 𝑥 < 8.3.12 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases