Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:3729-1

Опубликовано: 18 окт. 2024
Источник: suse-cvrf

Описание

Security update for php8

This update for php8 fixes the following issues:

Update to php 8.2.24:

  • CVE-2024-8925: Fixed erroneous parsing of multipart form data in HTTP POST requests leads to legitimate data not being processed (bsc#1231360)
  • CVE-2024-8927: Fixed cgi.force_redirect configuration is bypassable due to an environment variable collision (bsc#1231358)
  • CVE-2024-9026: Fixed pollution of worker output logs in PHP-FPM (bsc#1231382)

Список пакетов

Container bci/php-apache:latest
apache2-mod_php8-8.2.24-150600.3.6.1
php8-8.2.24-150600.3.6.1
php8-cli-8.2.24-150600.3.6.1
php8-curl-8.2.24-150600.3.6.1
php8-mbstring-8.2.24-150600.3.6.1
php8-openssl-8.2.24-150600.3.6.1
php8-phar-8.2.24-150600.3.6.1
php8-zip-8.2.24-150600.3.6.1
php8-zlib-8.2.24-150600.3.6.1
Container bci/php-fpm:latest
php8-8.2.24-150600.3.6.1
php8-cli-8.2.24-150600.3.6.1
php8-curl-8.2.24-150600.3.6.1
php8-fpm-8.2.24-150600.3.6.1
php8-mbstring-8.2.24-150600.3.6.1
php8-openssl-8.2.24-150600.3.6.1
php8-phar-8.2.24-150600.3.6.1
php8-zip-8.2.24-150600.3.6.1
php8-zlib-8.2.24-150600.3.6.1
Container bci/php:latest
php8-8.2.24-150600.3.6.1
php8-cli-8.2.24-150600.3.6.1
php8-curl-8.2.24-150600.3.6.1
php8-mbstring-8.2.24-150600.3.6.1
php8-openssl-8.2.24-150600.3.6.1
php8-phar-8.2.24-150600.3.6.1
php8-readline-8.2.24-150600.3.6.1
php8-zip-8.2.24-150600.3.6.1
php8-zlib-8.2.24-150600.3.6.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP6
apache2-mod_php8-8.2.24-150600.3.6.1
php8-8.2.24-150600.3.6.1
php8-bcmath-8.2.24-150600.3.6.1
php8-bz2-8.2.24-150600.3.6.1
php8-calendar-8.2.24-150600.3.6.1
php8-cli-8.2.24-150600.3.6.1
php8-ctype-8.2.24-150600.3.6.1
php8-curl-8.2.24-150600.3.6.1
php8-dba-8.2.24-150600.3.6.1
php8-devel-8.2.24-150600.3.6.1
php8-dom-8.2.24-150600.3.6.1
php8-embed-8.2.24-150600.3.6.1
php8-enchant-8.2.24-150600.3.6.1
php8-exif-8.2.24-150600.3.6.1
php8-fastcgi-8.2.24-150600.3.6.1
php8-fileinfo-8.2.24-150600.3.6.1
php8-fpm-8.2.24-150600.3.6.1
php8-ftp-8.2.24-150600.3.6.1
php8-gd-8.2.24-150600.3.6.1
php8-gettext-8.2.24-150600.3.6.1
php8-gmp-8.2.24-150600.3.6.1
php8-iconv-8.2.24-150600.3.6.1
php8-intl-8.2.24-150600.3.6.1
php8-ldap-8.2.24-150600.3.6.1
php8-mbstring-8.2.24-150600.3.6.1
php8-mysql-8.2.24-150600.3.6.1
php8-odbc-8.2.24-150600.3.6.1
php8-opcache-8.2.24-150600.3.6.1
php8-openssl-8.2.24-150600.3.6.1
php8-pcntl-8.2.24-150600.3.6.1
php8-pdo-8.2.24-150600.3.6.1
php8-pgsql-8.2.24-150600.3.6.1
php8-phar-8.2.24-150600.3.6.1
php8-posix-8.2.24-150600.3.6.1
php8-readline-8.2.24-150600.3.6.1
php8-shmop-8.2.24-150600.3.6.1
php8-snmp-8.2.24-150600.3.6.1
php8-soap-8.2.24-150600.3.6.1
php8-sockets-8.2.24-150600.3.6.1
php8-sodium-8.2.24-150600.3.6.1
php8-sqlite-8.2.24-150600.3.6.1
php8-sysvmsg-8.2.24-150600.3.6.1
php8-sysvsem-8.2.24-150600.3.6.1
php8-sysvshm-8.2.24-150600.3.6.1
php8-test-8.2.24-150600.3.6.1
php8-tidy-8.2.24-150600.3.6.1
php8-tokenizer-8.2.24-150600.3.6.1
php8-xmlreader-8.2.24-150600.3.6.1
php8-xmlwriter-8.2.24-150600.3.6.1
php8-xsl-8.2.24-150600.3.6.1
php8-zip-8.2.24-150600.3.6.1
php8-zlib-8.2.24-150600.3.6.1
openSUSE Leap 15.6
apache2-mod_php8-8.2.24-150600.3.6.1
php8-8.2.24-150600.3.6.1
php8-bcmath-8.2.24-150600.3.6.1
php8-bz2-8.2.24-150600.3.6.1
php8-calendar-8.2.24-150600.3.6.1
php8-cli-8.2.24-150600.3.6.1
php8-ctype-8.2.24-150600.3.6.1
php8-curl-8.2.24-150600.3.6.1
php8-dba-8.2.24-150600.3.6.1
php8-devel-8.2.24-150600.3.6.1
php8-dom-8.2.24-150600.3.6.1
php8-embed-8.2.24-150600.3.6.1
php8-enchant-8.2.24-150600.3.6.1
php8-exif-8.2.24-150600.3.6.1
php8-fastcgi-8.2.24-150600.3.6.1
php8-ffi-8.2.24-150600.3.6.1
php8-fileinfo-8.2.24-150600.3.6.1
php8-fpm-8.2.24-150600.3.6.1
php8-fpm-apache-8.2.24-150600.3.6.1
php8-ftp-8.2.24-150600.3.6.1
php8-gd-8.2.24-150600.3.6.1
php8-gettext-8.2.24-150600.3.6.1
php8-gmp-8.2.24-150600.3.6.1
php8-iconv-8.2.24-150600.3.6.1
php8-intl-8.2.24-150600.3.6.1
php8-ldap-8.2.24-150600.3.6.1
php8-mbstring-8.2.24-150600.3.6.1
php8-mysql-8.2.24-150600.3.6.1
php8-odbc-8.2.24-150600.3.6.1
php8-opcache-8.2.24-150600.3.6.1
php8-openssl-8.2.24-150600.3.6.1
php8-pcntl-8.2.24-150600.3.6.1
php8-pdo-8.2.24-150600.3.6.1
php8-pgsql-8.2.24-150600.3.6.1
php8-phar-8.2.24-150600.3.6.1
php8-posix-8.2.24-150600.3.6.1
php8-readline-8.2.24-150600.3.6.1
php8-shmop-8.2.24-150600.3.6.1
php8-snmp-8.2.24-150600.3.6.1
php8-soap-8.2.24-150600.3.6.1
php8-sockets-8.2.24-150600.3.6.1
php8-sodium-8.2.24-150600.3.6.1
php8-sqlite-8.2.24-150600.3.6.1
php8-sysvmsg-8.2.24-150600.3.6.1
php8-sysvsem-8.2.24-150600.3.6.1
php8-sysvshm-8.2.24-150600.3.6.1
php8-test-8.2.24-150600.3.6.1
php8-tidy-8.2.24-150600.3.6.1
php8-tokenizer-8.2.24-150600.3.6.1
php8-xmlreader-8.2.24-150600.3.6.1
php8-xmlwriter-8.2.24-150600.3.6.1
php8-xsl-8.2.24-150600.3.6.1
php8-zip-8.2.24-150600.3.6.1
php8-zlib-8.2.24-150600.3.6.1

Описание

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.


Затронутые продукты
Container bci/php-apache:latest:apache2-mod_php8-8.2.24-150600.3.6.1
Container bci/php-apache:latest:php8-8.2.24-150600.3.6.1
Container bci/php-apache:latest:php8-cli-8.2.24-150600.3.6.1
Container bci/php-apache:latest:php8-curl-8.2.24-150600.3.6.1

Ссылки

Описание

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.


Затронутые продукты
Container bci/php-apache:latest:apache2-mod_php8-8.2.24-150600.3.6.1
Container bci/php-apache:latest:php8-8.2.24-150600.3.6.1
Container bci/php-apache:latest:php8-cli-8.2.24-150600.3.6.1
Container bci/php-apache:latest:php8-curl-8.2.24-150600.3.6.1

Ссылки

Описание

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.


Затронутые продукты
Container bci/php-apache:latest:apache2-mod_php8-8.2.24-150600.3.6.1
Container bci/php-apache:latest:php8-8.2.24-150600.3.6.1
Container bci/php-apache:latest:php8-cli-8.2.24-150600.3.6.1
Container bci/php-apache:latest:php8-curl-8.2.24-150600.3.6.1

Ссылки
Уязвимость SUSE-SU-2024:3729-1