Описание
Security update for php7
This update for php7 fixes the following issues:
- CVE-2021-21705 [bsc#1188037]: SSRF bypass in FILTER_VALIDATE_URL
Список пакетов
openSUSE Leap 15.3
php7-pear-Archive_Tar-7.2.5-4.76.5
php7-wddx-7.2.5-4.76.5
Ссылки
- E-Mail link for openSUSE-SU-2021:2575-1
- SUSE Security Ratings
- SUSE Bug 1188037
- SUSE CVE CVE-2021-21705 page
Описание
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.
Затронутые продукты
openSUSE Leap 15.3:php7-pear-Archive_Tar-7.2.5-4.76.5
openSUSE Leap 15.3:php7-wddx-7.2.5-4.76.5
Ссылки
- CVE-2021-21705
- SUSE Bug 1188037