BIT-libphp-2024-8929

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/libphp/BIT-libphp-2024-8929.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-libphp-2024-8929
Aliases
Published
2025-08-11T13:54:31.347Z
Modified
2025-08-11T15:13:49.413007Z
Summary
Leak partial content of the heap through heap buffer over-read in mysqlnd
Details

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / libphp

Package

Name
libphp
Purl
pkg:bitnami/libphp

Severity

  • 5.8 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.1.31
Introduced
8.2.0
Fixed
8.2.24
Introduced
8.3.0
Fixed
8.3.14