The results of the security audit of the PHP codebase have been published

The OSTIF (Open Source Technology Improvement Fund), established to enhance the security of open projects, has announced the completion of an independent audit of the PHP project's core codebase. The work was performed by the French company QuarksLab, which has also been involved in auditing OpenVPN, VeraCrypt, and OpenSSL projects. The audit identified 27 issues, 17 of which are related to security, while 10 are informational. Two issues were classified as critical vulnerabilities, six have a medium severity level, and nine are deemed low risk.

Among the identified vulnerabilities:

  • CVE-2024-8928 — a vulnerability in the filter handler that leads to memory corruption.
  • CVE-2024-8929 — a vulnerability in the MySQL driver that results in memory content leaks due to reading data from out-of-bounds. Connecting to a compromised MySQL instance can lead to leaking details from other SQL queries. server A problem in PHP-FPM allows for a DoS attack by creating excessive CPU load.
  • Three medium-severity issues in the OpenSSL wrapper related to key alignment, IV overwriting, and lack of DH parameter checks. Plus, there are four low-risk issues in the OpenSSL wrapper.
  • Integer overflow when parsing php.ini.
  • CVE-2024-9026 — a vulnerability in PHP-FPM that allows characters to be removed from messages logged.
  • CVE-2024-8925 — an issue with parsing multipart forms that leads to incorrect data handling.
  • The OSTIF (Open Source Technology Improvement Fund), established to enhance the security of open projects, has announced the completion of an independent audit of the PHP project's core codebase.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster