INFSA-2025:4263: php:8.1 security update

Information about definition

Identificator: INFSA-2025:4263

Type: security

Release date: 2025-07-14 20:21:24 UTC

Information about package

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.

Vulnerabilities description

  • CVE-2024-11233

    In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.

  • CVE-2024-11234

    In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to use the proxy to perform arbitrary HTTP requests originating from the server, thus potentially gaining access to resources not normally available to the external user.

  • CVE-2024-8929

    In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

  • CVE-2025-1217

    A flaw was found in PHP. This vulnerability allows misinterpretation of HTTP response headers, potentially leading to incorrect usage of headers, MIME types, and other response attributes via incorrect parsing of folded headers in the HTTP request module.

  • CVE-2025-1219

    A flaw was found in PHP's DOM and SimpleXML extensions. This vulnerability allows incorrect parsing of a redirected HTTP resource via improper content-type header handling.

  • CVE-2025-1734

    A flaw was found in PHP. This vulnerability allows applications to accept invalid headers via malformed HTTP headers missing a colon (:), which may confuse applications into processing them as valid headers.

  • CVE-2025-1736

    A flaw was found in PHP. This vulnerability allows certain headers to be either not sent or misinterpreted due to insufficient validation of the end-of-line characters via user-supplied headers.

  • CVE-2025-1861

    A flaw was found in PHP. This vulnerability allows incorrect URL truncation and redirection to the wrong location via HTTP redirect handling due to a limited location buffer size.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 4.8 no information
no information 4.8 no information
NIST — CVE-2024-8929
no information 5.8 no information
NIST — CVE-2025-1217
no information 3.7 no information
NIST — CVE-2025-1219
no information 3.7 no information
NIST — CVE-2025-1734
no information 3.7 no information
NIST — CVE-2025-1736
no information 3.7 no information
NIST — CVE-2025-1861
no information 5.3 no information
Critical, important, moderate, low

Updated packages