VDB
DEBIAN-CVE-2025-1220
DEBIAN-CVE-2025-1220
PUBLISHED
CVSS 5.300000190734863 MEDIUM
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
Risk Scores
CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | php8.2 | 8.2.7-1.1, 8.2.10-1, 8.2.10-2 |
| Debian:14 | php8.4 | 0, 0 |
| Debian:13 | php8.4 | 0, 0 |
| Debian:11 | php7.4 | 7.4.28-1+deb11u1, 7.4.33-1+deb11u3, 7.4.33-1+deb11u5 |
Timeline
- Jul 13, 2025 CVE Published
- Apr 28, 2026 CVE Updated