SB2025042841 - Red Hat Enterprise Linux 9 update for the php:8.1 module
Published: April 28, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 secuirty vulnerabilities.
1) Buffer Over-read (CVE-ID: CVE-2024-8929)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due memory leak within the MySQLnd component. A
remote attacker can force the application to leak partial content of
the heap and gain access to sensitive information.
2) Buffer Over-read (CVE-ID: CVE-2024-11233)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a one byte over-read in streams when using the convert.quoted-printable-decode filter. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
3) CRLF injection (CVE-ID: CVE-2024-11234)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insufficient validation of URIs in streams component when using proxy. A remote attacker can pass specially crafted data to the application containing CR-LF characters and perform a spoofing attack.
4) Input validation error (CVE-ID: CVE-2025-1217)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to Header parser of HTTP Stream wrapper does not handle folded headers. A remote attacker can perform spoofing attack by manipulating HTTP headers.
5) Improper Authentication (CVE-ID: CVE-2025-1736)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in Stream HTTP wrapper header check, which can omit Basic authentication header. A remote attacker can bypass authentication mechanisms that rely on Basic authentication.
6) Input validation error (CVE-ID: CVE-2025-1734)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the Streams HTTP wrapper does not fail for headers without a colon. A remote attacker can potentially perform header injection, which can lead to a spoofing attack.
7) Resource management error (CVE-ID: CVE-2025-1219)
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists in libxml streams due to usage of an incorrect Content-Type header when requesting a redirected resource. A remote attacker can leverage this vulnerability to perform content spoofing or XSS attacks.
8) Input validation error (CVE-ID: CVE-2025-1861)
The vulnerability allows a remote attacker to redirect the application to a malicious URL.
The vulnerability exists due to insufficient validation of user-supplied input. The Stream HTTP wrapper truncates redirect location to 1024 bytes, which can lead to the application being redirected to a wrong URL.
Remediation
Install update from vendor's website.