Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-7431

Опубликовано: 22 мая 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-7431: php security update (MODERATE)

[8.0.30-3]

  • Fix libxml streams use wrong content-type header when requesting a redirected resource CVE-2025-1219
  • Fix Stream HTTP wrapper header check might omit basic auth header CVE-2025-1736
  • Fix Stream HTTP wrapper truncate redirect location to 1024 bytes CVE-2025-1861
  • Fix Streams HTTP wrapper does not fail for headers without colon CVE-2025-1734
  • Fix Header parser of http stream wrapper does not handle folded headers CVE-2025-1217

[8.0.30-2]

  • Fix Leak partial content of the heap through heap buffer over-read CVE-2024-8929
  • Fix Configuring a proxy in a stream context might allow for CRLF injection in URIs CVE-2024-11234
  • Fix Single byte overread with convert.quoted-printable-decode filter CVE-2024-11233
  • Fix cgi.force_redirect configuration is bypassable due to the environment variable collision CVE-2024-8927
  • Fix Logs from childrens may be altered CVE-2024-9026
  • Fix Erroneous parsing of multipart form data CVE-2024-8925
  • Fix filter bypass in filter_var FILTER_VALIDATE_URL CVE-2024-5458
  • Fix __Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix CVE-2024-2756
  • Fix password_verify can erroneously return true opening ATO risk CVE-2024-3096

[8.0.30-1]

  • rebase to 8.0.30
  • Resolves: RHEL-11946

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

php

8.0.30-3.el9_6

php-bcmath

8.0.30-3.el9_6

php-cli

8.0.30-3.el9_6

php-common

8.0.30-3.el9_6

php-dba

8.0.30-3.el9_6

php-dbg

8.0.30-3.el9_6

php-devel

8.0.30-3.el9_6

php-embedded

8.0.30-3.el9_6

php-enchant

8.0.30-3.el9_6

php-ffi

8.0.30-3.el9_6

php-fpm

8.0.30-3.el9_6

php-gd

8.0.30-3.el9_6

php-gmp

8.0.30-3.el9_6

php-intl

8.0.30-3.el9_6

php-ldap

8.0.30-3.el9_6

php-mbstring

8.0.30-3.el9_6

php-mysqlnd

8.0.30-3.el9_6

php-odbc

8.0.30-3.el9_6

php-opcache

8.0.30-3.el9_6

php-pdo

8.0.30-3.el9_6

php-pgsql

8.0.30-3.el9_6

php-process

8.0.30-3.el9_6

php-snmp

8.0.30-3.el9_6

php-soap

8.0.30-3.el9_6

php-xml

8.0.30-3.el9_6

Oracle Linux x86_64

php

8.0.30-3.el9_6

php-bcmath

8.0.30-3.el9_6

php-cli

8.0.30-3.el9_6

php-common

8.0.30-3.el9_6

php-dba

8.0.30-3.el9_6

php-dbg

8.0.30-3.el9_6

php-devel

8.0.30-3.el9_6

php-embedded

8.0.30-3.el9_6

php-enchant

8.0.30-3.el9_6

php-ffi

8.0.30-3.el9_6

php-fpm

8.0.30-3.el9_6

php-gd

8.0.30-3.el9_6

php-gmp

8.0.30-3.el9_6

php-intl

8.0.30-3.el9_6

php-ldap

8.0.30-3.el9_6

php-mbstring

8.0.30-3.el9_6

php-mysqlnd

8.0.30-3.el9_6

php-odbc

8.0.30-3.el9_6

php-opcache

8.0.30-3.el9_6

php-pdo

8.0.30-3.el9_6

php-pgsql

8.0.30-3.el9_6

php-process

8.0.30-3.el9_6

php-snmp

8.0.30-3.el9_6

php-soap

8.0.30-3.el9_6

php-xml

8.0.30-3.el9_6

Связанные уязвимости

suse-cvrf
3 месяца назад

Security update for php7

suse-cvrf
3 месяца назад

Security update for php7

suse-cvrf
3 месяца назад

Security update for php8

suse-cvrf
3 месяца назад

Security update for php8

oracle-oval
28 дней назад

ELSA-2025-7418: php:8.3 security update (IMPORTANT)