CBL Mariner 2.0 Security Update: php (CVE-2025-6491)
Discription

The version of php installed on the remote CBL Mariner 2.0 host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the CVE-2025-6491 advisory. In PHP versions:8.1. before 8.1.33, 8.2. before 8.2.29, 8.3. before 8.3.23, 8.4. before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix May lead to null pointer dereference. This May lead to crashes and affect the availability of the target server. (CVE-2025-6491) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number. File data…Read More
References
Back to Main