Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-5468

Опубликовано: 04 июл. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-5468: php:8.0 security update (IMPORTANT)

php [8.0.13-3]

  • fix password of excessive length triggers buffer overflow leading to RCE CVE-2022-31626

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module php:8.0 is enabled

apcu-panel

5.1.20-1.module+el8.6.0+20568+84712317

libzip

1.7.3-1.module+el8.6.0+20568+84712317

libzip-devel

1.7.3-1.module+el8.6.0+20568+84712317

libzip-tools

1.7.3-1.module+el8.6.0+20568+84712317

php

8.0.13-3.module+el8.6.0+20694+4397942f

php-bcmath

8.0.13-3.module+el8.6.0+20694+4397942f

php-cli

8.0.13-3.module+el8.6.0+20694+4397942f

php-common

8.0.13-3.module+el8.6.0+20694+4397942f

php-dba

8.0.13-3.module+el8.6.0+20694+4397942f

php-dbg

8.0.13-3.module+el8.6.0+20694+4397942f

php-devel

8.0.13-3.module+el8.6.0+20694+4397942f

php-embedded

8.0.13-3.module+el8.6.0+20694+4397942f

php-enchant

8.0.13-3.module+el8.6.0+20694+4397942f

php-ffi

8.0.13-3.module+el8.6.0+20694+4397942f

php-fpm

8.0.13-3.module+el8.6.0+20694+4397942f

php-gd

8.0.13-3.module+el8.6.0+20694+4397942f

php-gmp

8.0.13-3.module+el8.6.0+20694+4397942f

php-intl

8.0.13-3.module+el8.6.0+20694+4397942f

php-ldap

8.0.13-3.module+el8.6.0+20694+4397942f

php-mbstring

8.0.13-3.module+el8.6.0+20694+4397942f

php-mysqlnd

8.0.13-3.module+el8.6.0+20694+4397942f

php-odbc

8.0.13-3.module+el8.6.0+20694+4397942f

php-opcache

8.0.13-3.module+el8.6.0+20694+4397942f

php-pdo

8.0.13-3.module+el8.6.0+20694+4397942f

php-pear

1.10.13-1.module+el8.6.0+20568+84712317

php-pecl-apcu

5.1.20-1.module+el8.6.0+20568+84712317

php-pecl-apcu-devel

5.1.20-1.module+el8.6.0+20568+84712317

php-pecl-rrd

2.0.3-1.module+el8.6.0+20568+84712317

php-pecl-xdebug3

3.1.2-1.module+el8.6.0+20568+84712317

php-pecl-zip

1.19.2-1.module+el8.6.0+20568+84712317

php-pgsql

8.0.13-3.module+el8.6.0+20694+4397942f

php-process

8.0.13-3.module+el8.6.0+20694+4397942f

php-snmp

8.0.13-3.module+el8.6.0+20694+4397942f

php-soap

8.0.13-3.module+el8.6.0+20694+4397942f

php-xml

8.0.13-3.module+el8.6.0+20694+4397942f

Oracle Linux x86_64

Module php:8.0 is enabled

apcu-panel

5.1.20-1.module+el8.6.0+20568+84712317

libzip

1.7.3-1.module+el8.6.0+20568+84712317

libzip-devel

1.7.3-1.module+el8.6.0+20568+84712317

libzip-tools

1.7.3-1.module+el8.6.0+20568+84712317

php

8.0.13-3.module+el8.6.0+20694+4397942f

php-bcmath

8.0.13-3.module+el8.6.0+20694+4397942f

php-cli

8.0.13-3.module+el8.6.0+20694+4397942f

php-common

8.0.13-3.module+el8.6.0+20694+4397942f

php-dba

8.0.13-3.module+el8.6.0+20694+4397942f

php-dbg

8.0.13-3.module+el8.6.0+20694+4397942f

php-devel

8.0.13-3.module+el8.6.0+20694+4397942f

php-embedded

8.0.13-3.module+el8.6.0+20694+4397942f

php-enchant

8.0.13-3.module+el8.6.0+20694+4397942f

php-ffi

8.0.13-3.module+el8.6.0+20694+4397942f

php-fpm

8.0.13-3.module+el8.6.0+20694+4397942f

php-gd

8.0.13-3.module+el8.6.0+20694+4397942f

php-gmp

8.0.13-3.module+el8.6.0+20694+4397942f

php-intl

8.0.13-3.module+el8.6.0+20694+4397942f

php-ldap

8.0.13-3.module+el8.6.0+20694+4397942f

php-mbstring

8.0.13-3.module+el8.6.0+20694+4397942f

php-mysqlnd

8.0.13-3.module+el8.6.0+20694+4397942f

php-odbc

8.0.13-3.module+el8.6.0+20694+4397942f

php-opcache

8.0.13-3.module+el8.6.0+20694+4397942f

php-pdo

8.0.13-3.module+el8.6.0+20694+4397942f

php-pear

1.10.13-1.module+el8.6.0+20568+84712317

php-pecl-apcu

5.1.20-1.module+el8.6.0+20568+84712317

php-pecl-apcu-devel

5.1.20-1.module+el8.6.0+20568+84712317

php-pecl-rrd

2.0.3-1.module+el8.6.0+20568+84712317

php-pecl-xdebug3

3.1.2-1.module+el8.6.0+20568+84712317

php-pecl-zip

1.19.2-1.module+el8.6.0+20568+84712317

php-pgsql

8.0.13-3.module+el8.6.0+20694+4397942f

php-process

8.0.13-3.module+el8.6.0+20694+4397942f

php-snmp

8.0.13-3.module+el8.6.0+20694+4397942f

php-soap

8.0.13-3.module+el8.6.0+20694+4397942f

php-xml

8.0.13-3.module+el8.6.0+20694+4397942f

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 8.8
redhat
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 7.5
nvd
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 7.5
debian
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x belo ...

rocky
почти 3 года назад

Important: php:8.0 security update