CVE-2024-8929
EUVD-2024-4963822.11.2024, 07:15
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| php | php | 8.1.0 ≤ 𝑥 < 8.1.31 |
| php | php | 8.2.0 ≤ 𝑥 < 8.2.26 |
| php | php | 8.3.0 ≤ 𝑥 < 8.3.14 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| php_group | php | 8.1.0 ≤ 𝑥 < 8.1.31 | ADP |
| php_group | php | 8.2.0 ≤ 𝑥 < 8.2.24 | ADP |
| php_group | php | 8.3.0 ≤ 𝑥 < 8.3.14 | ADP |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| php5 |
| ||||||||||||||
| php7.0 |
| ||||||||||||||
| php7.2 |
| ||||||||||||||
| php7.4 |
| ||||||||||||||
| php8.1 |
| ||||||||||||||
| php8.3 |
|
Common Weakness Enumeration