CVE-2023-0568
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/02/2023
Last modified:
13/02/2025
Description
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | 8.0.0 (including) | 8.0.28 (excluding) |
| cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | 8.1.0 (including) | 8.1.16 (excluding) |
| cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | 8.2.0 (including) | 8.2.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



