Описание
Security update for php8
This update for php8 fixes the following issues:
-
CVE-2022-37454: Fixed buffer overflow in hash_update() on long parameter (bug#81738) (bsc#1204577).
-
CVE-2022-31630: Fixed OOB read due to insufficient input validation in imageloadfont() (bug#81739) (bsc#1204979).
-
version update to 8.0.25 (27 Oct 2022)
- Session: Fixed bug GH-9583 (session_create_id() fails with user defined save handler that doesn't have a validateId() method).
- Streams: Fixed bug GH-9590 (stream_select does not abort upon exception or empty valid fd set).
Список пакетов
Container bci/php-apache:8
Container bci/php-apache:latest
Container bci/php-fpm:8
Container bci/php-fpm:latest
Container bci/php:8
Container bci/php:latest
SUSE Linux Enterprise Module for Web and Scripting 15 SP4
openSUSE Leap 15.4
Ссылки
- Link for SUSE-SU-2022:4005-1
- E-Mail link for SUSE-SU-2022:4005-1
- SUSE Security Ratings
- SUSE Bug 1204577
- SUSE Bug 1204979
- SUSE CVE CVE-2022-31630 page
- SUSE CVE CVE-2022-37454 page
Описание
In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.
Затронутые продукты
Ссылки
- CVE-2022-31630
- SUSE Bug 1204979
Описание
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
Затронутые продукты
Ссылки
- CVE-2022-37454
- SUSE Bug 1204577
- SUSE Bug 1204966
- SUSE Bug 1205836