In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in phpreadstreamallchunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.
{
"binaries": [
{
"binary_name": "libapache2-mod-php8.3",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "libphp8.3-embed",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-bcmath",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-bz2",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-cgi",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-cli",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-common",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-curl",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-dba",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-dev",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-enchant",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-fpm",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-gd",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-gmp",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-imap",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-interbase",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-intl",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-ldap",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-mbstring",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-mysql",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-odbc",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-opcache",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-pgsql",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-phpdbg",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-pspell",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-readline",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-snmp",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-soap",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-sqlite3",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-sybase",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-tidy",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-xml",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-xsl",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
},
{
"binary_name": "php8.3-zip",
"binary_version": "8.3.6-0ubuntu0.24.04.5"
}
]
}
{
"binaries": [
{
"binary_name": "libapache2-mod-php8.4",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "libphp8.4-embed",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-bcmath",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-bz2",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-cgi",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-cli",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-common",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-curl",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-dba",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-dev",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-enchant",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-fpm",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-gd",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-gmp",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-interbase",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-intl",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-ldap",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-mbstring",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-mysql",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-odbc",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-opcache",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-pgsql",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-phpdbg",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-readline",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-snmp",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-soap",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-sqlite3",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-sybase",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-tidy",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-xml",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-xsl",
"binary_version": "8.4.11-1ubuntu1"
},
{
"binary_name": "php8.4-zip",
"binary_version": "8.4.11-1ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "libapache2-mod-php8.4",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "libphp8.4-embed",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-bcmath",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-bz2",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-cgi",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-cli",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-common",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-curl",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-dba",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-dev",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-enchant",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-fpm",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-gd",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-gmp",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-interbase",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-intl",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-ldap",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-mbstring",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-mysql",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-odbc",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-opcache",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-pgsql",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-phpdbg",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-readline",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-snmp",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-soap",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-sqlite3",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-sybase",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-tidy",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-xml",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-xsl",
"binary_version": "8.4.5-1ubuntu1.1"
},
{
"binary_name": "php8.4-zip",
"binary_version": "8.4.5-1ubuntu1.1"
}
]
}