Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-5904

Опубликовано: 04 авг. 2022
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2022-5904: php security update (IMPORTANT)

[8.0.13-2]

  • fix password of excessive length triggers buffer overflow leading to RCE CVE-2022-31626

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

php

8.0.13-2.el9_0

php-bcmath

8.0.13-2.el9_0

php-cli

8.0.13-2.el9_0

php-common

8.0.13-2.el9_0

php-dba

8.0.13-2.el9_0

php-dbg

8.0.13-2.el9_0

php-devel

8.0.13-2.el9_0

php-embedded

8.0.13-2.el9_0

php-enchant

8.0.13-2.el9_0

php-ffi

8.0.13-2.el9_0

php-fpm

8.0.13-2.el9_0

php-gd

8.0.13-2.el9_0

php-gmp

8.0.13-2.el9_0

php-intl

8.0.13-2.el9_0

php-ldap

8.0.13-2.el9_0

php-mbstring

8.0.13-2.el9_0

php-mysqlnd

8.0.13-2.el9_0

php-odbc

8.0.13-2.el9_0

php-opcache

8.0.13-2.el9_0

php-pdo

8.0.13-2.el9_0

php-pgsql

8.0.13-2.el9_0

php-process

8.0.13-2.el9_0

php-snmp

8.0.13-2.el9_0

php-soap

8.0.13-2.el9_0

php-xml

8.0.13-2.el9_0

Oracle Linux x86_64

php

8.0.13-2.el9_0

php-bcmath

8.0.13-2.el9_0

php-cli

8.0.13-2.el9_0

php-common

8.0.13-2.el9_0

php-dba

8.0.13-2.el9_0

php-dbg

8.0.13-2.el9_0

php-devel

8.0.13-2.el9_0

php-embedded

8.0.13-2.el9_0

php-enchant

8.0.13-2.el9_0

php-ffi

8.0.13-2.el9_0

php-fpm

8.0.13-2.el9_0

php-gd

8.0.13-2.el9_0

php-gmp

8.0.13-2.el9_0

php-intl

8.0.13-2.el9_0

php-ldap

8.0.13-2.el9_0

php-mbstring

8.0.13-2.el9_0

php-mysqlnd

8.0.13-2.el9_0

php-odbc

8.0.13-2.el9_0

php-opcache

8.0.13-2.el9_0

php-pdo

8.0.13-2.el9_0

php-pgsql

8.0.13-2.el9_0

php-process

8.0.13-2.el9_0

php-snmp

8.0.13-2.el9_0

php-soap

8.0.13-2.el9_0

php-xml

8.0.13-2.el9_0

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 8.8
redhat
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 7.5
nvd
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 7.5
debian
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x belo ...

rocky
почти 3 года назад

Important: php:8.0 security update

Уязвимость ELSA-2022-5904