• 公告ID (KylinSec-SA-2022-1185)

摘要:

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

安全等级: Low

公告ID: KylinSec-SA-2022-1185

发布日期: 2022年11月18日

关联CVE: CVE-2019-11049  

  • 详细介绍

1. 漏洞描述

   

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2019-11049 KY3.4-4A php Unaffected
CVE-2019-11049 KY3.4-5A php Unaffected
CVE-2019-11049 KY3.5.1 php Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2020-1873 下一篇:KylinSec-SA-2022-1186