CVE-2024-4577
Description
PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
CISA KEV
- Vendor
- PHP Group
- Product
- PHP
- Due date
- 2024-07-03
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://www.php.net/ChangeLog-8.php#; https://nvd.nist.gov/vuln/detail/CVE-2024-4577
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-4577
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-4577.html
Exploits
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bullseye | fixed | 0 |
| debian | bookworm | fixed | 0 |
References
- https://www.suse.com/security/cve/CVE-2024-4577.html
- https://security-tracker.debian.org/tracker/CVE-2024-4577
- This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://www.php.net/ChangeLog-8.php#; https://nvd.nist.gov/vuln/detail/CVE-2024-4577
Verify integrity in audit chain (admin only). AS-IS.