Bug 2379792 (CVE-2025-1220) - CVE-2025-1220 php: PHP Hostname Null Character Vulnerability
Summary: CVE-2025-1220 php: PHP Hostname Null Character Vulnerability
Keywords:
Status: NEW
Alias: CVE-2025-1220
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2379848 2379849
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-07-13 23:01 UTC by OSIDB Bzimport
Modified: 2025-09-12 18:57 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-07-13 23:01:10 UTC
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.

Comment 2 Ron Gould 2025-09-12 18:57:25 UTC
CVE state is currently "Fix Deferred". Is there a plan to fix this for Red Hat 8.10 for DNF Module php:8.2?


Note You need to log in before you can comment on or make changes to this bug.