QID 356771

Date Published: 2023-12-06

QID 356771: Amazon Linux Security Advisory for Hypertext Preprocessor (PHP) : ALAS2-2023-2375

An issue was discovered in oniguruma 6.2.0, as used in oniguruma-mod in ruby through 2.4.1 and mbstring in php through 7.1.5.
A heap out-of-bounds write occurs in bitset_set_range() during regular expression compilation due to an uninitialized variable from an incorrect state transition.
An incorrect state transition in parse_char_class() could create an execution path that leaves a critical local variable uninitialized until it's used as an index, resulting in an out-of-bounds write memory corruption. (
( CVE-2017-9228) an issue was discovered in oniguruma 6.2.0, as used in oniguruma-mod in ruby through 2.4.1 and mbstring in php through 7.1.5.
A sigsegv occurs in left_adjust_char_head() during regular expression compilation.
Invalid handling of reg->dmax in forward_search_range() could result in an invalid pointer dereference, normally as an immediate denial-of-service condition. (
( CVE-2017-9229) a vulnerability was found in php due to an uninitialized array in pg_query_params() function.
When using the postgres database extension, supplying invalid parameters to the parameterized query may lead to php attempting to free memory, using uninitialized data as pointers.
This flaw allows a remote attacker with the ability to control query parameters to execute arbitrary code on the system or may cause a denial of service. (
( CVE-2022-31625) in php 8.0.x before 8.0.28, 8.1.x before 8.1.16 and 8.2.x before 8.2.3, excessive number of parts in http form upload can cause high resource consumption and excessive number of log entries.
This can cause denial of service on the affected server by exhausting cpu resources or disk space. (

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2-2023-2375 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 356771

    Software Advisories
    Advisory ID Software Component Link
    ALAS2-2023-2375 amazon linux 2 URL Logo alas.aws.amazon.com/AL2/ALAS-2023-2375.html