OS Command Injection in PHP - CVE-2024-1874
Published: April 11, 2024 / Updated: July 19, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing array-ish $command parameter of proc_open. A remote attacker can pass specially crafted input to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Storage Sentinel Anomaly Scan Engine
EasyApache
Slackware Linux
Anolis OS
Fedora
Oracle Solaris
php81
php
php-intl
php-zip
php-ldap
php-mbstring
php-mysqlnd
php-odbc
php-opcache
php-pdo
php-pgsql
php-process
php-snmp
php-soap
php-sodium
php-xml
php-gmp
php-gd
php-fpm
php-ffi
php-enchant
php-embedded
php-devel
php-dbg
php-dba
php-common
php-cli
php-bcmath
How to mitigate CVE-2024-1874
EasyApache - update to 4 2024-6-10
php81 - addressed in versions 8.1.28, 8.1.29
php - addressed in versions 8.2.18-1.fc38, 8.2.18-1.fc39, 8.3.5-1.fc40
php-intl - update to 8.2.20-1
php-zip - update to 8.2.20-1
php-ldap - update to 8.2.20-1
php-mbstring - update to 8.2.20-1
php-mysqlnd - update to 8.2.20-1
php-odbc - update to 8.2.20-1
php-opcache - update to 8.2.20-1
php-pdo - update to 8.2.20-1
php-pgsql - update to 8.2.20-1
php-process - update to 8.2.20-1
php-snmp - update to 8.2.20-1
php-soap - update to 8.2.20-1
php-sodium - update to 8.2.20-1
php-xml - update to 8.2.20-1
php-gmp - update to 8.2.20-1
php-gd - update to 8.2.20-1
php-fpm - update to 8.2.20-1
php-ffi - update to 8.2.20-1
php-enchant - update to 8.2.20-1
php-embedded - update to 8.2.20-1
php-devel - update to 8.2.20-1
php-dbg - update to 8.2.20-1
php-dba - update to 8.2.20-1
php-common - update to 8.2.20-1
php-cli - update to 8.2.20-1
php-bcmath - update to 8.2.20-1
php - update to 8.2.20-1
Oracle Solaris - update to 11.4 SRU 71
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in PHP
- Fedora 40 update for php
- Fedora 39 update for php
- Fedora 38 update for php
- Slackware Linux update for php
- Slackware Linux update for php
- Oracle Solaris update for thrid-party components
- cPanel EasyApache update for PHP
- Anolis OS update for php
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine