In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "libapache2-mod-php7.4"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "libphp7.4-embed"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-bcmath"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-bz2"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-cgi"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-cli"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-common"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-curl"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-dba"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-dev"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-enchant"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-fpm"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-gd"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-gmp"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-imap"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-interbase"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-intl"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-json"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-ldap"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-mbstring"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-mysql"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-odbc"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-opcache"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-pgsql"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-phpdbg"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-pspell"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-readline"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-snmp"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-soap"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-sqlite3"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-sybase"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-tidy"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-xml"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-xmlrpc"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-xsl"
},
{
"binary_version": "7.4.3-4ubuntu1.1",
"binary_name": "php7.4-zip"
}
]
}