Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:8197

Опубликовано: 15 нояб. 2022
Источник: rocky
Оценка: Moderate

Описание

Moderate: php security, bug fix, and enhancement update

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.

The following packages have been upgraded to a later upstream version: php (8.0.20). (BZ#2095752)

Security Fix(es):

  • php: Use after free due to php_filter_float() failing for ints (CVE-2021-21708)

  • php: Uninitialized array in pg_query_params() leading to RCE (CVE-2022-31625)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
phpx86_643.el9php-8.0.20-3.el9.x86_64.rpm
php-bcmathx86_643.el9php-bcmath-8.0.20-3.el9.x86_64.rpm
php-clix86_643.el9php-cli-8.0.20-3.el9.x86_64.rpm
php-commonx86_643.el9php-common-8.0.20-3.el9.x86_64.rpm
php-dbax86_643.el9php-dba-8.0.20-3.el9.x86_64.rpm
php-dbgx86_643.el9php-dbg-8.0.20-3.el9.x86_64.rpm
php-develx86_643.el9php-devel-8.0.20-3.el9.x86_64.rpm
php-embeddedx86_643.el9php-embedded-8.0.20-3.el9.x86_64.rpm
php-enchantx86_643.el9php-enchant-8.0.20-3.el9.x86_64.rpm
php-ffix86_643.el9php-ffi-8.0.20-3.el9.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

rocky
больше 2 лет назад

Moderate: php:8.0 security, bug fix, and enhancement update

oracle-oval
больше 2 лет назад

ELSA-2022-8197: php security, bug fix, and enhancement update (MODERATE)

oracle-oval
больше 2 лет назад

ELSA-2022-7624: php:8.0 security, bug fix, and enhancement update (MODERATE)

suse-cvrf
больше 2 лет назад

Security update for php7

CVSS3: 8.1
ubuntu
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.