Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:2575-1

Опубликовано: 30 июл. 2021
Источник: suse-cvrf

Описание

Security update for php7

This update for php7 fixes the following issues:

  • CVE-2021-21705 [bsc#1188037]: SSRF bypass in FILTER_VALIDATE_URL

Список пакетов

openSUSE Leap 15.3
php7-pear-Archive_Tar-7.2.5-4.76.5
php7-wddx-7.2.5-4.76.5

Описание

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.


Затронутые продукты
openSUSE Leap 15.3:php7-pear-Archive_Tar-7.2.5-4.76.5
openSUSE Leap 15.3:php7-wddx-7.2.5-4.76.5

Ссылки