Описание
Security update for php74
This update for php74 fixes the following issues:
- CVE-2022-31631: Fixed an issue where PDO::quote would return an unquoted string (bsc#1206958).
Список пакетов
SUSE Linux Enterprise Module for Web and Scripting 12
SUSE Linux Enterprise Software Development Kit 12 SP5
Ссылки
- Link for SUSE-SU-2023:0072-1
- E-Mail link for SUSE-SU-2023:0072-1
- SUSE Security Ratings
- SUSE Bug 1206958
- SUSE Bug 923946
- SUSE Bug 935227
- SUSE CVE CVE-2014-9709 page
- SUSE CVE CVE-2015-3411 page
- SUSE CVE CVE-2022-31631 page
Описание
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.
Затронутые продукты
Ссылки
- CVE-2014-9709
- SUSE Bug 923945
- SUSE Bug 923946
- SUSE Bug 980366
Описание
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.
Затронутые продукты
Ссылки
- CVE-2015-3411
- SUSE Bug 935074
- SUSE Bug 935227
- SUSE Bug 935229
- SUSE Bug 935232
- SUSE Bug 980366
Описание
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
Затронутые продукты
Ссылки
- CVE-2022-31631
- SUSE Bug 1206958