Bug 2214967 - TRIAGE php: stack information leak in PHP's implementation of SOAP HTTP Digest authentication
Summary: TRIAGE php: stack information leak in PHP's implementation of SOAP HTTP Diges...
Keywords:
Status: NEW
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2214968 2214969
Blocks: 2214970
TreeView+ depends on / blocked
 
Reported: 2023-06-14 09:08 UTC by Sandipan Roy
Modified: 2023-10-06 09:06 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2023-06-14 09:08:29 UTC
It was discovered that PHP's implementation of SOAP HTTP Digest
authentication performed insufficient error validation, which may result
in a stack information leak or use of weak randomness.

Ref: https://packetstormsecurity.com/files/172900/dsa-5424-1.txt

Comment 2 Remi Collet 2023-06-14 11:51:04 UTC
PHP upstream considers this issue as "low", so don't issue any CVE for it

Comment 4 Remi Collet 2023-10-06 09:06:01 UTC
Notice: this issue is https://github.com/php/php-src/security/advisories/GHSA-76gg-c692-v2mw

Was assigned CVE-2023-3247 

Was fixed in 8.0.29, 8.1.20 and 8.2.7


Note You need to log in before you can comment on or make changes to this bug.