Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-1935

Опубликовано: 17 мая 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-1935: php:7.4 security update (MODERATE)

libzip [1.6.1-1]

  • update to 1.6.1
  • enable lzma support

php-pear [1:1.10.12-1]

  • update PEAR to 1.10.12
  • update Archive_Tar to 1.4.9
  • update Console_Getopt to 1.4.3
  • update XML_Util to 1.4.5

php-pecl-apcu [5.1.18-1]

  • update to 5.1.18

php-pecl-rrd php-pecl-xdebug [2.9.5-1]

  • update to 2.9.5

php-pecl-zip [1.18.2-1]

  • update to 1.18.2

php [7.4.19-2]

  • fix SSRF bypass in FILTER_VALIDATE_URL CVE-2021-21705
  • fix Local privilege escalation via PHP-FPM CVE-2021-21703

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module php:7.4 is enabled

apcu-panel

5.1.18-1.module+el8.3.0+7685+72d70b58

libzip

1.6.1-1.module+el8.3.0+7685+72d70b58

libzip-devel

1.6.1-1.module+el8.3.0+7685+72d70b58

libzip-tools

1.6.1-1.module+el8.3.0+7685+72d70b58

php

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-bcmath

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-cli

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-common

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-dba

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-dbg

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-devel

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-embedded

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-enchant

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-ffi

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-fpm

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-gd

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-gmp

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-intl

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-json

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-ldap

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-mbstring

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-mysqlnd

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-odbc

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-opcache

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-pdo

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-pear

1.10.12-1.module+el8.3.0+7685+72d70b58

php-pecl-apcu

5.1.18-1.module+el8.3.0+7685+72d70b58

php-pecl-apcu-devel

5.1.18-1.module+el8.3.0+7685+72d70b58

php-pecl-rrd

2.0.1-1.module+el8.3.0+7685+72d70b58

php-pecl-xdebug

2.9.5-1.module+el8.3.0+7685+72d70b58

php-pecl-zip

1.18.2-1.module+el8.3.0+7685+72d70b58

php-pgsql

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-process

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-snmp

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-soap

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-xml

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-xmlrpc

7.4.19-2.module+el8.6.0+20552+0a59ce9f

Oracle Linux x86_64

Module php:7.4 is enabled

apcu-panel

5.1.18-1.module+el8.3.0+7685+72d70b58

libzip

1.6.1-1.module+el8.3.0+7685+72d70b58

libzip-devel

1.6.1-1.module+el8.3.0+7685+72d70b58

libzip-tools

1.6.1-1.module+el8.3.0+7685+72d70b58

php

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-bcmath

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-cli

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-common

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-dba

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-dbg

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-devel

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-embedded

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-enchant

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-ffi

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-fpm

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-gd

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-gmp

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-intl

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-json

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-ldap

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-mbstring

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-mysqlnd

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-odbc

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-opcache

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-pdo

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-pear

1.10.12-1.module+el8.3.0+7685+72d70b58

php-pecl-apcu

5.1.18-1.module+el8.3.0+7685+72d70b58

php-pecl-apcu-devel

5.1.18-1.module+el8.3.0+7685+72d70b58

php-pecl-rrd

2.0.1-1.module+el8.3.0+7685+72d70b58

php-pecl-xdebug

2.9.5-1.module+el8.3.0+7685+72d70b58

php-pecl-zip

1.18.2-1.module+el8.3.0+7685+72d70b58

php-pgsql

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-process

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-snmp

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-soap

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-xml

7.4.19-2.module+el8.6.0+20552+0a59ce9f

php-xmlrpc

7.4.19-2.module+el8.6.0+20552+0a59ce9f

Связанные CVE

Связанные уязвимости

rocky
около 3 лет назад

Moderate: php:7.4 security update

CVSS3: 4.3
ubuntu
почти 4 года назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.

CVSS3: 5.3
redhat
около 4 лет назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.

CVSS3: 4.3
nvd
почти 4 года назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.

CVSS3: 4.3
debian
почти 4 года назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below ...