OS Command Injection in PHP - CVE-2024-5585

 

OS Command Injection in PHP - CVE-2024-5585

Published: June 5, 2024 / Updated: June 7, 2024


Vulnerability identifier: #VU91109
CSH Severity: Medium
CVSS v4 BT: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-5585
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to insufficient fix for #VU88482 (CVE-2024-1874). A remote attacker can pass specially crafted input to the application and execute arbitrary OS commands on the target system.


Affected software

PHP
Gentoo Linux
Slackware Linux
Anolis OS
Fedora
Oracle Solaris
Storage Sentinel Anomaly Scan Engine
EasyApache
Communications Unified Assurance
SecurityCenter
php81
php-snmp
php-intl
php-ldap
php-mbstring
php-mysqlnd
php-odbc
php-opcache
php-pdo
php-pgsql
php-process
php-fpm
php-soap
php-sodium
php-xml
php-zip
php-gmp
php-gd
php-ffi
php-enchant
php-embedded
php-devel
php-dbg
php-dba
php-common
php-cli
php-bcmath
php

How to mitigate CVE-2024-5585

Install updates from vendor's website.

PHP - addressed in versions 8.1.29, 8.2.20, 8.3.8
EasyApache - update to 4 2024-6-10
Communications Unified Assurance - update to 6.0.5
SecurityCenter - update to SC-202412.1
php81 - update to 8.1.29
php-snmp - update to 8.2.20-1
php-intl - update to 8.2.20-1
php-ldap - update to 8.2.20-1
php-mbstring - update to 8.2.20-1
php-mysqlnd - update to 8.2.20-1
php-odbc - update to 8.2.20-1
php-opcache - update to 8.2.20-1
php-pdo - update to 8.2.20-1
php-pgsql - update to 8.2.20-1
php-process - update to 8.2.20-1
php-fpm - update to 8.2.20-1
php-soap - update to 8.2.20-1
php-sodium - update to 8.2.20-1
php-xml - update to 8.2.20-1
php-zip - update to 8.2.20-1
php-gmp - update to 8.2.20-1
php-gd - update to 8.2.20-1
php-ffi - update to 8.2.20-1
php-enchant - update to 8.2.20-1
php-embedded - update to 8.2.20-1
php-devel - update to 8.2.20-1
php-dbg - update to 8.2.20-1
php-dba - update to 8.2.20-1
php-common - update to 8.2.20-1
php-cli - update to 8.2.20-1
php-bcmath - update to 8.2.20-1
php - update to 8.2.20-1
php - addressed in versions 8.2.20-1.fc39, 8.3.8-1.fc40
Oracle Solaris - update to 11.4 SRU 71

External References

Related Security Bulletins