Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2019:3735

Опубликовано: 06 нояб. 2019
Источник: rocky
Оценка: Critical

Описание

Critical: php:7.2 security update

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.

Security Fix(es):

  • php: underflow in env_path_info in fpm_main.c (CVE-2019-11043)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
apcu-panelnoarch2.module+el8.4.0+413+c9202ddaapcu-panel-5.1.12-2.module+el8.4.0+413+c9202dda.noarch.rpm
libzipx86_642.module+el8.4.0+413+c9202ddalibzip-1.5.1-2.module+el8.4.0+413+c9202dda.x86_64.rpm
libzip-develx86_642.module+el8.4.0+413+c9202ddalibzip-devel-1.5.1-2.module+el8.4.0+413+c9202dda.x86_64.rpm
libzip-toolsx86_642.module+el8.4.0+413+c9202ddalibzip-tools-1.5.1-2.module+el8.4.0+413+c9202dda.x86_64.rpm
php-pearnoarch9.module+el8.4.0+413+c9202ddaphp-pear-1.10.5-9.module+el8.4.0+413+c9202dda.noarch.rpm
php-pecl-apcux86_642.module+el8.4.0+413+c9202ddaphp-pecl-apcu-5.1.12-2.module+el8.4.0+413+c9202dda.x86_64.rpm
php-pecl-apcu-develx86_642.module+el8.4.0+413+c9202ddaphp-pecl-apcu-devel-5.1.12-2.module+el8.4.0+413+c9202dda.x86_64.rpm
php-pecl-zipx86_641.module+el8.4.0+413+c9202ddaphp-pecl-zip-1.15.3-1.module+el8.4.0+413+c9202dda.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.7
ubuntu
больше 5 лет назад

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVSS3: 8.1
redhat
больше 5 лет назад

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVSS3: 8.7
nvd
больше 5 лет назад

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVSS3: 8.7
debian
больше 5 лет назад

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below ...

suse-cvrf
больше 5 лет назад

Security update for php7