CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*

History

02 Jul 2025, 20:08

Type Values Removed Values Added
References () https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff - () https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20250110-0009/ - () https://security.netapp.com/advisory/ntap-20250110-0009/ - Third Party Advisory
CPE cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
First Time Netapp
Php php
Php
Netapp ontap

10 Jan 2025, 13:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250110-0009/ -
Summary
  • (es) En las versiones de PHP 8.1.* anteriores a 8.1.31, 8.2.* anteriores a 8.2.26, 8.3.* anteriores a 8.3.14, las entradas de cadenas largas no controladas a la función ldap_escape() en sistemas de 32 bits pueden causar un desbordamiento de enteros, lo que resulta en una escritura fuera de los límites.

22 Nov 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-22 06:15

Updated : 2025-07-02 20:08


NVD link : CVE-2024-8932

Mitre link : CVE-2024-8932

CVE.ORG link : CVE-2024-8932


JSON object : View

Products Affected

netapp

  • ontap

php

  • php
CWE
CWE-787

Out-of-bounds Write