Untriaged
PDO::quote() may return unquoted string
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
Affected products
pdo_sqlite
- <8.2.2
- <8.0.27
- <8.1.15
Matching in nixpkgs
pkgs.php81Extensions.pdo_sqlite
PHP upstream extension: pdo_sqlite
-
nixos-unstable -
- nixpkgs-unstable 8.1.33
pkgs.php82Extensions.pdo_sqlite
PHP upstream extension: pdo_sqlite
-
nixos-unstable -
- nixpkgs-unstable 8.2.29
pkgs.php83Extensions.pdo_sqlite
PHP upstream extension: pdo_sqlite
-
nixos-unstable -
- nixpkgs-unstable 8.3.25
pkgs.php84Extensions.pdo_sqlite
PHP upstream extension: pdo_sqlite
-
nixos-unstable -
- nixpkgs-unstable 8.4.12
Package maintainers
-
@aanderse Aaron Andersen <aaron@fosslib.net>
-
@piotrkwiecinski Piotr Kwiecinski <piokwiecinski+nixpkgs@gmail.com>
-
@Ma27 Maximilian Bosch <maximilian@mbosch.me>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>