Null byte termination in dns_get_record()

Inhalt

Summary

As GHSA-3cr5-j632-f35r, same null termination is occuring

Details

dns_get_record() and other DNS functions don't have any null contain check, leads potential SSRF or unexpected behavior.

PoC

No data

Quellen-Details

Bezeichnung Name Kategorie Tags Zielgruppe Sprache Feed-URL
PHP Security (php/php-src GHSA)

php_sec

vendor_advisory php, runtime - de https://github.com/php/php-src/security/advisories