Logo
componentphp8
Name
php8
Version
8.4.21-r
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:php:php:8.4.21:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
8.4.16-r4

Patches#


#
Title
Author
Resolve
1
Use system timezone
Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>
2
Patch #2
Unknown
3
Add-support-for-use-of-the-system-timezone-database
Debian PHP Maintainers <team+pkg-php@tracker.debian.org>
4
Patch #4
Unknown
5
php-5.4.9-fixheader
Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>
6
Patch #6
Unknown
7
Patch #7
Unknown

Vulnerabilities#


Name
Analysis
Description
Exploitable
The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.