CVE-2024-9026
08.10.2024, 04:15
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it isconfigured to catch workers output through catch_workers_output = yes,it may be possible to pollute the final log orremove up to 4 characters from the log messages by manipulating log message content. Additionally, ifPHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 8.1.30 < 𝑥 < 8.1.30 |
php | php | 8.2.24 < 𝑥 < 8.2.24 |
php | php | 8.3.12 < 𝑥 < 8.3.12 |
php-fpm | php-fpm | 8.1.0 ≤ 𝑥 < 8.1.30 |
php-fpm | php-fpm | 8.2.0 ≤ 𝑥 < 8.2.24 |
php-fpm | php-fpm | 8.3.0 ≤ 𝑥 < 8.3.12 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
php5 |
| ||||||||
php7.0 |
| ||||||||
php7.2 |
| ||||||||
php7.4 |
| ||||||||
php8.1 |
| ||||||||
php8.3 |
|
Common Weakness Enumeration