CVE-2024-57071

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 5, 2025
Updated: Feb 6, 2025
CWE ID 1321

Summary

CVE-2024-57071 is a vulnerability affecting the lib.combine function in php-parser version 3.2.1. Attackers can exploit this prototype pollution flaw to cause a Denial of Service (DoS) by supplying specially crafted input. This vulnerability allows an attacker to overwrite memory buffers, resulting in the application crashing or becoming unresponsive. The impact of this issue is significant as it can lead to service disruptions for end-users, making it essential for users of php-parser to upgrade to a patched version as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share