CVE-2024-11233

HIGH8.2EPSS 0.73%

Single byte overread with convert.quoted-printable-decode filter

Published: 11/24/2024Modified: 4/28/2026
Also known as:DEBIAN-CVE-2024-11233

Description

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

Affected packages (7)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

References (5)