CVE-2023-0568

Array overrun in common path resolve code

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.


We have discovered 353,546 live websites that are affected by CVE-2023-0568.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains353,546 live websites (4.05% of PHP install base)
Vulnerable Versions
  • from 8 before 8.0.28
  • from 8.1 before 8.1.16
  • from 8.2 before 8.2.3
Vulnerable Versions Count47 versions ( 8.59% of all versions)


Common Weakness Enumeration

CWE-131 Incorrect Calculation of Buffer Size



Details

  • Published - Feb 16, 2023
  • Updated - Feb 13, 2025

Credits

  • Niels Dossche (finder)

CVE-2023-0568 usage by Country

United States230,213 websites



France76,266 websites
Germany8,417 websites
Russia4,482 websites
Netherlands4,367 websites
Brazil3,384 websites
Poland2,441 websites
Spain2,192 websites
GB2,148 websites
Japan1,473 websites

CVE-2023-0568 usage by TLD

.com200,302 websites
.fr30,042 websites
.org25,153 websites
.net10,180 websites
.de6,614 websites
.ca6,298 websites
.co.uk5,786 websites
.nl5,423 websites
.ru5,016 websites
.be4,459 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-0568

Top websites that are affected by CVE-2023-0568. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States***
******.com United States*,***
****.com China*,***
***************.org United States*,***
*********.com United States*,***
******.org United States*,***
**********.edu United States*,***
***************.com United States*,***
***************.com Singapore*,***
***********.com United States*,***
See full domain list

FAQ

CVE-2023-0568 is Incorrect Calculation of Buffer Size in PHP
A total of 353,546 websites have been identified as vulnerable to CVE-2023-0568, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2023-0568 vulnerability.
PHP versions before 8.2.3 are vulnerable to CVE-2023-0568.
Version 8.2.3 of PHP addresses the CVE-2023-0568 security vulnerability.