HomeDefectsLIN1024-388
Acknowledged

LIN1024-388 : Security Advisory - php - CVE-2024-2757

Created: Apr 29, 2024    Updated: Jan 7, 2026
Resolved Date: Jun 16, 2024
Found In Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function. 

https://nvd.nist.gov/vuln/detail/CVE-2024-2757