Korean
<< Back
VID 22959
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description According to its self-reported version number, the version of PHP running on the remote web server is prior to 7.3.24. It is, therefore affected by multiple vulnerabilities

Core:
Fixed bug #79423 (copy command is limited to size of file it can copy).

Calendar:
Fixed bug #80185 (jdtounix() fails after 2037).

IMAP:
Fixed bug #80213 (imap_mail_compose() segfaults on certain $bodies).
Fixed bug #80215 (imap_mail_compose() may modify by-val parameters).
Fixed bug #80220 (imap_mail_compose() may leak memory).
Fixed bug #80223 (imap_mail_compose() leaks envelope on malformed bodies).
Fixed bug #80216 (imap_mail_compose() does not validate types/encodings).
Fixed bug #80226 (imap_sort() leaks sortpgm memory).

MySQLnd:
Fixed bug #80115 (mysqlnd.debug doesn't recognize absolute paths with slashes).
Fixed bug #80107 (mysqli_query() fails for ~16 MB long query when compression is enabled).

ODBC:
Fixed bug #78470 (odbc_specialcolumns() no longer accepts $nullable).
Fixed bug #80147 (BINARY strings may not be properly zero-terminated).
Fixed bug #80150 (Failure to fetch error message).
Fixed bug #80152 (odbc_execute() moves internal pointer of $params).
Fixed bug #46050 (odbc_next_result corrupts prepared resource).

OPcache:
Fixed bug #80083 (Optimizer pass 6 removes variables used for ibm_db2 data binding).

PDO_ODBC:
Fixed bug #67465 (NULL Pointer dereference in odbc_handle_preparer).

Standard:
Fixed bug #80114 (parse_url does not accept URLs with port 0).
Fixed bug #76943 (Inconsistent stream_wrapper_restore() errors).
Fixed bug #76735 (Incorrect message in fopen on invalid mode).

Tidy:
Fixed bug #77040 (tidyNode::isHtml() is completely broken).

* References:
https://www.php.net/ChangeLog-7.php#7.3.24

* Platforms Affected:
PHP Prior to 7.3.24
Any operating system Any version
Recommendation Upgrade to the latest version of PHP (7.3.24 or later), available from the PHP web site at http://www.php.net/downloads.php
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)