QID 38869

Date Published: 2022-06-01

QID 38869: Hypertext Preprocessor (PHP) Use After free Vulnerability

PHP is a general purpose scripting language that is especially suited for web development and can be embedded into HTML.

Affected Versions:
PHP 7.4.0 prior to version 7.4.28
PHP 8.0.0 prior to version 8.0.16
PHP 8.1.0 prior to version 8.1.3

QID Detection Logic
The qid checks the php version via banner.

A successful exploit may lead to use after free and remote code execution

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to the latest versions 7.4.28, 8.0.16, 8.1.3.
    Vendor References

    CVEs related to QID 38869

    Software Advisories
    Advisory ID Software Component Link
    81708 URL Logo bugs.php.net/bug.php?id=81708