Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian: DLA-3345-1 Critical: PHP Denial Of Service Issues

debian lts
Calendar Grey February 26, 2023
Dist Debian Esm H88
Numerous vulnerabilities identified in Python may result in system crashes or flawed Argon2 hash verification; recommended to update.

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service or incorrect validation of BCry...

Summary

CVE-2022-31631

Due to an uncaught integer overflow, `PDO::quote()` of PDO_SQLite
may return an improperly quoted string. The exact details likely
depend on the implementation of `sqlite3_snprintf()`, but with some
versions it is possible to force the function to return a single
apostrophe, if the function is called on user supplied input without
any length restrictions in place.

CVE-2023-0567

Tim Düsterhus discovered that malformed BCrypt hashes that include a
`$` within their salt part trigger a buffer overread and may
erroneously validate any password as valid. (`Password_verify()`
always return `true` with such inputs.)

CVE-2023-0568

1-byte array overrun when appending slash to paths during path
resolution.

CVE-2023-0662

Jakob Ackermann discovered a Denial of Service vulnerability when
parsing multipart request body: the request body parsing in PHP
allows any unauthenticated attacker to consume a large amount of CPU

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: php7.3
Version: 7.3.31-1~deb10u3
CVE ID: CVE-2022-31631 CVE-2023-0567 CVE-2023-0568 CVE-2023-0662
Debian Bug: 1031368

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here