PHP修補重大層級的記憶體越界寫入漏洞
支付動態 · 2024-11-27

上週PHP開發團隊發布安全性更新,其中修補重大層級的越界寫入漏洞CVE-2024-8932最為危險,而受到關注

11月21日PHP開發團隊發布8.3.14、8.2.26、8.1.31版,主要修補一項重大層級的漏洞CVE-2024-8932,這項弱點可被用於越界寫入(OBW),CVSS風險評為9.8。

開發團隊指出,這項弱點存在於32位元的系統,起因是在名為ldap_escape()的功能裡,若是輸入不受控制的長字串,就有可能導致整數溢位的情形。

他們也提及這項弱點影響4.56.2及以前版本的HipHop Virtual Machine(HHVM)虛擬機器,此外,介於4.57.0與4.83.0之間多個版本HHVM,也會曝險。

Popular articles
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
DB Gaming Is One of Asia’s Top-Tier Game Solution Providers, Recognized as a Pioneer in the Asian Gaming Industry.
Marketing
PropellerAds Positions Itself as a Go-To Traffic Source for iGaming Advertisers Ahead of a High-Demand Season
Marketing
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
Kazakhstan plans to penalise online casino promotions
Regulation
Zenith partners with HUIDU for 2026 World Cup Carnival Official Tour
Online Game
What’s on the SBC Summit Conference Agenda in 2026?
Marketing
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
Global Game Connect (GGC) 2027 Officially Opens Sponsorship & Exhibition Opportunities in Sri Lanka!
HUIDU Focus
British gambling levy rates confirmed for each vertical
Regulation
Home
Game
Cooperation
Find
My