In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libapache2-mod-php7.4", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "libphp7.4-embed", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-bcmath", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-bz2", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-cgi", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-cli", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-common", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-curl", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-dba", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-dev", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-enchant", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-fpm", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-gd", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-gmp", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-imap", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-interbase", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-intl", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-json", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-ldap", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-mbstring", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-mysql", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-odbc", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-opcache", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-pgsql", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-phpdbg", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-pspell", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-readline", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-snmp", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-soap", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-sqlite3", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-sybase", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-tidy", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-xml", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-xmlrpc", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-xsl", "binary_version": "7.4.3-4ubuntu1.1" }, { "binary_name": "php7.4-zip", "binary_version": "7.4.3-4ubuntu1.1" } ] }