OS Command Injection in PHP - CVE-2024-5585
Published: June 5, 2024 / Updated: June 7, 2024
Vulnerability identifier: #VU91109
CSH Severity: Medium
CVSS v4 BT: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-5585
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to insufficient fix for #VU88482 (CVE-2024-1874). A remote attacker can pass specially crafted input to the application and execute arbitrary OS commands on the target system.
Affected software
PHP
Gentoo Linux
Slackware Linux
Anolis OS
Fedora
Oracle Solaris
Storage Sentinel Anomaly Scan Engine
EasyApache
Communications Unified Assurance
SecurityCenter
php81
php-snmp
php-intl
php-ldap
php-mbstring
php-mysqlnd
php-odbc
php-opcache
php-pdo
php-pgsql
php-process
php-fpm
php-soap
php-sodium
php-xml
php-zip
php-gmp
php-gd
php-ffi
php-enchant
php-embedded
php-devel
php-dbg
php-dba
php-common
php-cli
php-bcmath
php
Gentoo Linux
Slackware Linux
Anolis OS
Fedora
Oracle Solaris
Storage Sentinel Anomaly Scan Engine
EasyApache
Communications Unified Assurance
SecurityCenter
php81
php-snmp
php-intl
php-ldap
php-mbstring
php-mysqlnd
php-odbc
php-opcache
php-pdo
php-pgsql
php-process
php-fpm
php-soap
php-sodium
php-xml
php-zip
php-gmp
php-gd
php-ffi
php-enchant
php-embedded
php-devel
php-dbg
php-dba
php-common
php-cli
php-bcmath
php
How to mitigate CVE-2024-5585
Install updates from vendor's website.
PHP - addressed in versions 8.1.29, 8.2.20, 8.3.8
EasyApache - update to 4 2024-6-10
Communications Unified Assurance - update to 6.0.5
SecurityCenter - update to SC-202412.1
php81 - update to 8.1.29
php-snmp - update to 8.2.20-1
php-intl - update to 8.2.20-1
php-ldap - update to 8.2.20-1
php-mbstring - update to 8.2.20-1
php-mysqlnd - update to 8.2.20-1
php-odbc - update to 8.2.20-1
php-opcache - update to 8.2.20-1
php-pdo - update to 8.2.20-1
php-pgsql - update to 8.2.20-1
php-process - update to 8.2.20-1
php-fpm - update to 8.2.20-1
php-soap - update to 8.2.20-1
php-sodium - update to 8.2.20-1
php-xml - update to 8.2.20-1
php-zip - update to 8.2.20-1
php-gmp - update to 8.2.20-1
php-gd - update to 8.2.20-1
php-ffi - update to 8.2.20-1
php-enchant - update to 8.2.20-1
php-embedded - update to 8.2.20-1
php-devel - update to 8.2.20-1
php-dbg - update to 8.2.20-1
php-dba - update to 8.2.20-1
php-common - update to 8.2.20-1
php-cli - update to 8.2.20-1
php-bcmath - update to 8.2.20-1
php - update to 8.2.20-1
php - addressed in versions 8.2.20-1.fc39, 8.3.8-1.fc40
Oracle Solaris - update to 11.4 SRU 71
EasyApache - update to 4 2024-6-10
Communications Unified Assurance - update to 6.0.5
SecurityCenter - update to SC-202412.1
php81 - update to 8.1.29
php-snmp - update to 8.2.20-1
php-intl - update to 8.2.20-1
php-ldap - update to 8.2.20-1
php-mbstring - update to 8.2.20-1
php-mysqlnd - update to 8.2.20-1
php-odbc - update to 8.2.20-1
php-opcache - update to 8.2.20-1
php-pdo - update to 8.2.20-1
php-pgsql - update to 8.2.20-1
php-process - update to 8.2.20-1
php-fpm - update to 8.2.20-1
php-soap - update to 8.2.20-1
php-sodium - update to 8.2.20-1
php-xml - update to 8.2.20-1
php-zip - update to 8.2.20-1
php-gmp - update to 8.2.20-1
php-gd - update to 8.2.20-1
php-ffi - update to 8.2.20-1
php-enchant - update to 8.2.20-1
php-embedded - update to 8.2.20-1
php-devel - update to 8.2.20-1
php-dbg - update to 8.2.20-1
php-dba - update to 8.2.20-1
php-common - update to 8.2.20-1
php-cli - update to 8.2.20-1
php-bcmath - update to 8.2.20-1
php - update to 8.2.20-1
php - addressed in versions 8.2.20-1.fc39, 8.3.8-1.fc40
Oracle Solaris - update to 11.4 SRU 71
External References
Related Security Bulletins
- Multiple vulnerabilities in PHP
- Fedora 39 update for php
- Fedora 40 update for php
- Slackware Linux update for php
- Oracle Solaris update for thrid-party components
- Gentoo update for PHP
- Multiple vulnerabilities in Communications Unified Assurance
- cPanel EasyApache update for PHP
- Multiple vulnerabilities in Tenable Security Center
- Anolis OS update for php
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine