Executive brief
A buffer overflow vulnerability in the PHP FastCGI Process Manager (FPM) allows an attacker to write past allocated buffers into space reserved for FCGI protocol data. This flaw can be exploited in certain FPM configurations to achieve remote code execution.
Affected products
- PHP Group PHP 7.1.x below 7.1.33, 7.2.x below 7.2.24, 7.3.x below 7.3.11
Timeline
- 2019-10-24: disclosed: Initial bug report and patch development on PHP bug tracker.
- 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2022-03-25: advisory: NVD publication date.
- 2022-03-25: exploited: Confirmed exploited in the wild per CISA KEV.