Severity
5.5MEDIUMNVD
CNA6.2GHSA5.0
EPSS
0.1%
top 79.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 2
Latest updateMay 2

Description

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

NVDphp/php< 8.0.22

Also affects: Enterprise Linux 6.0, 7.0, 8.0, 9.0

🔴Vulnerability Details

6
OSV
php7.4, php8.1, php8.2 vulnerabilities2024-05-02
OSV
php7.0, php7.2, php7.4, php8.1 vulnerabilities2024-04-29
OSV
CVE-2022-4900: A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow2023-11-02
GHSA
GHSA-95cc-jq89-8hvw: A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow2023-11-02
CVEList
Potential buffer overflow in php_cli_server_startup_workers2023-11-02

📋Vendor Advisories

4
Ubuntu
PHP vulnerabilities2024-05-02
Ubuntu
PHP vulnerabilities2024-04-29
Red Hat
php: potential buffer overflow in php_cli_server_startup_workers2022-07-13
Debian
CVE-2022-4900: php7.4 - A vulnerability was found in PHP where setting the environment variable PHP_CLI_...2022
CVE-2022-4900 — PHP vulnerability | cvebase