n PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.
| Link | Resource |
|---|---|
| https://github.com/php/php-src/security/advisories/GHSA-3237-qqm7-mfv7 | Exploit Third Party Advisory |
Configuration 1 (hide)
|
08 Jan 2026, 22:03
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:a:php:php:8.5.0:*:*:*:*:*:*:* cpe:2.3:a:php:php:*:*:*:*:*:*:*:* |
|
| References | () https://github.com/php/php-src/security/advisories/GHSA-3237-qqm7-mfv7 - Exploit, Third Party Advisory | |
| First Time |
Php
Php php |
27 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-12-27 20:15
Updated : 2026-01-08 22:03
NVD link : CVE-2025-14177
Mitre link : CVE-2025-14177
CVE.ORG link : CVE-2025-14177
JSON object : View
Out-of-bounds Read