Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-5467

Опубликовано: 04 июл. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-5467: php:7.4 security update (IMPORTANT)

php [7.4.19-3]

  • fix password of excessive length triggers buffer overflow leading to RCE CVE-2022-31626

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module php:7.4 is enabled

apcu-panel

5.1.18-1.module+el8.3.0+7685+72d70b58

libzip

1.6.1-1.module+el8.3.0+7685+72d70b58

libzip-devel

1.6.1-1.module+el8.3.0+7685+72d70b58

libzip-tools

1.6.1-1.module+el8.3.0+7685+72d70b58

php

7.4.19-3.module+el8.6.0+20697+59319e67

php-bcmath

7.4.19-3.module+el8.6.0+20697+59319e67

php-cli

7.4.19-3.module+el8.6.0+20697+59319e67

php-common

7.4.19-3.module+el8.6.0+20697+59319e67

php-dba

7.4.19-3.module+el8.6.0+20697+59319e67

php-dbg

7.4.19-3.module+el8.6.0+20697+59319e67

php-devel

7.4.19-3.module+el8.6.0+20697+59319e67

php-embedded

7.4.19-3.module+el8.6.0+20697+59319e67

php-enchant

7.4.19-3.module+el8.6.0+20697+59319e67

php-ffi

7.4.19-3.module+el8.6.0+20697+59319e67

php-fpm

7.4.19-3.module+el8.6.0+20697+59319e67

php-gd

7.4.19-3.module+el8.6.0+20697+59319e67

php-gmp

7.4.19-3.module+el8.6.0+20697+59319e67

php-intl

7.4.19-3.module+el8.6.0+20697+59319e67

php-json

7.4.19-3.module+el8.6.0+20697+59319e67

php-ldap

7.4.19-3.module+el8.6.0+20697+59319e67

php-mbstring

7.4.19-3.module+el8.6.0+20697+59319e67

php-mysqlnd

7.4.19-3.module+el8.6.0+20697+59319e67

php-odbc

7.4.19-3.module+el8.6.0+20697+59319e67

php-opcache

7.4.19-3.module+el8.6.0+20697+59319e67

php-pdo

7.4.19-3.module+el8.6.0+20697+59319e67

php-pear

1.10.12-1.module+el8.3.0+7685+72d70b58

php-pecl-apcu

5.1.18-1.module+el8.3.0+7685+72d70b58

php-pecl-apcu-devel

5.1.18-1.module+el8.3.0+7685+72d70b58

php-pecl-rrd

2.0.1-1.module+el8.3.0+7685+72d70b58

php-pecl-xdebug

2.9.5-1.module+el8.3.0+7685+72d70b58

php-pecl-zip

1.18.2-1.module+el8.3.0+7685+72d70b58

php-pgsql

7.4.19-3.module+el8.6.0+20697+59319e67

php-process

7.4.19-3.module+el8.6.0+20697+59319e67

php-snmp

7.4.19-3.module+el8.6.0+20697+59319e67

php-soap

7.4.19-3.module+el8.6.0+20697+59319e67

php-xml

7.4.19-3.module+el8.6.0+20697+59319e67

php-xmlrpc

7.4.19-3.module+el8.6.0+20697+59319e67

Oracle Linux x86_64

Module php:7.4 is enabled

apcu-panel

5.1.18-1.module+el8.3.0+7685+72d70b58

libzip

1.6.1-1.module+el8.3.0+7685+72d70b58

libzip-devel

1.6.1-1.module+el8.3.0+7685+72d70b58

libzip-tools

1.6.1-1.module+el8.3.0+7685+72d70b58

php

7.4.19-3.module+el8.6.0+20697+59319e67

php-bcmath

7.4.19-3.module+el8.6.0+20697+59319e67

php-cli

7.4.19-3.module+el8.6.0+20697+59319e67

php-common

7.4.19-3.module+el8.6.0+20697+59319e67

php-dba

7.4.19-3.module+el8.6.0+20697+59319e67

php-dbg

7.4.19-3.module+el8.6.0+20697+59319e67

php-devel

7.4.19-3.module+el8.6.0+20697+59319e67

php-embedded

7.4.19-3.module+el8.6.0+20697+59319e67

php-enchant

7.4.19-3.module+el8.6.0+20697+59319e67

php-ffi

7.4.19-3.module+el8.6.0+20697+59319e67

php-fpm

7.4.19-3.module+el8.6.0+20697+59319e67

php-gd

7.4.19-3.module+el8.6.0+20697+59319e67

php-gmp

7.4.19-3.module+el8.6.0+20697+59319e67

php-intl

7.4.19-3.module+el8.6.0+20697+59319e67

php-json

7.4.19-3.module+el8.6.0+20697+59319e67

php-ldap

7.4.19-3.module+el8.6.0+20697+59319e67

php-mbstring

7.4.19-3.module+el8.6.0+20697+59319e67

php-mysqlnd

7.4.19-3.module+el8.6.0+20697+59319e67

php-odbc

7.4.19-3.module+el8.6.0+20697+59319e67

php-opcache

7.4.19-3.module+el8.6.0+20697+59319e67

php-pdo

7.4.19-3.module+el8.6.0+20697+59319e67

php-pear

1.10.12-1.module+el8.3.0+7685+72d70b58

php-pecl-apcu

5.1.18-1.module+el8.3.0+7685+72d70b58

php-pecl-apcu-devel

5.1.18-1.module+el8.3.0+7685+72d70b58

php-pecl-rrd

2.0.1-1.module+el8.3.0+7685+72d70b58

php-pecl-xdebug

2.9.5-1.module+el8.3.0+7685+72d70b58

php-pecl-zip

1.18.2-1.module+el8.3.0+7685+72d70b58

php-pgsql

7.4.19-3.module+el8.6.0+20697+59319e67

php-process

7.4.19-3.module+el8.6.0+20697+59319e67

php-snmp

7.4.19-3.module+el8.6.0+20697+59319e67

php-soap

7.4.19-3.module+el8.6.0+20697+59319e67

php-xml

7.4.19-3.module+el8.6.0+20697+59319e67

php-xmlrpc

7.4.19-3.module+el8.6.0+20697+59319e67

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 8.8
redhat
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 7.5
nvd
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 7.5
debian
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x belo ...

rocky
почти 3 года назад

Important: php:8.0 security update