Описание
Security update for php-composer2
This update for php-composer2 fixes the following issues:
CVE-2025-67746: Fixed ANSI control characters injection in the terminal output of various Composer commands via attacker controlled remote sources. (bsc#1255768)
Список пакетов
SUSE Linux Enterprise Module for Web and Scripting 15 SP7
openSUSE Leap 15.6
Ссылки
- Link for SUSE-SU-2026:0825-1
- E-Mail link for SUSE-SU-2026:0825-1
- SUSE Security Ratings
- SUSE Bug 1255768
- SUSE CVE CVE-2025-67746 page
Описание
Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in the terminal output of various Composer commands, causing mangled output and potentially leading to confusion or DoS of the terminal application. There is no proven exploit and this has thus a low severity but we still publish a CVE as it has potential for abuse, and we want to be on the safe side informing users that they should upgrade. Versions 2.2.26 and 2.9.3 contain a patch for the issue.
Затронутые продукты
Ссылки
- CVE-2025-67746
- SUSE Bug 1255768