CVE-2025-14180
CVSS 7.5 HIGH: in PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before… EPSS 0.7% (52º percentile).
Vulnerabilità ed exploit
Debian ha rilasciato un aggiornamento php8.2 per bookworm che risolve tre vulnerabilità (CVE-2025-14177, CVE-2025-14178, CVE-2025-14180). Le vulnerabilità possono causare denial of service o memory disclosure. Le correzioni sono incluse in php8.2 8.2.30-1~deb12u1.
1 fonte · 2 mar
CVSS 7.5 HIGH: in PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before… EPSS 0.7% (52º percentile).
CVSS 7.5 HIGH: in PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before… EPSS 0.5% (42º percentile).
CVSS 6.5 MEDIUM: in PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before… EPSS 0.5% (39º percentile).
Debian Security Advisories
SECURITY] [DSA 6154-1] php8.2 security update
SECURITY] [DSA 6154-1] php8.2 security update -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - Debian Security Advisory DSA-6154-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 02, 2026 https://www.debian.org/security/faq - Package : php8.2 CVE ID…
originalePart of the PlainSec briefing for 2026-03-02
Every edition of this story: Aggiornamento php8.2 chiude falle DoS e memory disclosure