发布时间: 2024年10月12日
修改时间: 2024年10月12日
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.
NVD | openEuler | |
---|---|---|
Confidentiality | None | None |
Attack Vector | Network | Network |
CVSS评分 | 5.3 | 3.1 |
Attack Complexity | Low | High |
Privileges Required | None | Low |
Scope | Unchanged | Unchanged |
Integrity | Low | Low |
User Interaction | None | None |
Availability | None | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-4097 | php security update | 2025年2月8日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5 | php | Fixed |
KY3.5.2 | php | Fixed |
KY3.5.3 | php | Fixed |
V6 | php | Fixed |