Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian LTS DLA-3555-1 Critical: PHP 7.3 RCE And DoS Vulnerabilities

debian lts
Calendar Grey September 5, 2023
Dist Debian Esm H88
Debian LTS Bulletin DLA-3556-1 tackles vulnerabilities in Python, safeguarding systems. Update Python immediately!
Security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in information disclosure, denial of service or potentially remo...

Summary

CVE-2023-3823

Various XML functions rely on libxml global state to track
configuration variables, like whether external entities are loaded.
This state is assumed to be unchanged unless the user explicitly
changes it by calling appropriate function. Joas Schilling and
Baptista Katapi discovered that, since the state is process-global,
other modules — such as ImageMagick — may also use this library
within the same process and change that global state for their
internal purposes, and leave it in a state where external entities
loading is enabled. This can lead to the situation where external
XML is parsed with external entities loaded, which can lead to
disclosure of any local files accessible to PHP. This vulnerable
state may persist in the same process across many requests, until
the process is shut down.

CVE-2023-3824

Niels Dossche discovered that when loading a Phar file, while

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: php7.3
Version: 7.3.31-1~deb10u5
CVE ID: CVE-2023-3823 CVE-2023-3824

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here