Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 38: FEDORA-2023-ee5acda059 Important: Composer Security Flaw Exposed

fedora
Calendar Grey October 15, 2023
Dist Fedora Esm H88
Fedora's recent update for Composer includes crucial security fixes to combat potential vulnerabilities and enhance safety against remote code execution risks.
**Version 2.6.5** - 2023-10-06 * Fixed error when vendor dir contains broken symlinks (#11670) * Fixed composer.lock missing from Composer's zip archives (#11674) * Fixed Autolo...

Summary

Composer helps you declare, manage and install dependencies of PHP projects,

ensuring you have the right stack everywhere.

Documentation: https://getcomposer.org/doc/

Update Information:

**Version 2.6.5** - 2023-10-06 * Fixed error when vendor dir contains broken symlinks (#11670) * Fixed composer.lock missing from Composer's zip archives (#11674) * Fixed AutoloadGenerator::dump() non-BC signature change in 2.6.4 (cb363b0e8) ---- **Version 2.6.4** - 2023-09-29 * Security: Fixed possible remote code execution vulnerability if composer.phar is publicly accessible, executable as PHP, and register_argc_argv is enabled in php.ini (GHSA-jm6m-4632-36hf / **CVE-2023-43655**) * Fixed json output of abandoned packages in audit command (#11647) * Performance improvement in pool optimization step (#11638) * Performance improvement in `show -a ` (#11659)

Change Log

* Fri Oct 6 2023 Remi Collet - 2.6.5-1 - update to 2.6.5 * Fri Sep 29 2023 Remi Collet - 2.6.4-1 - update to 2.6.4

References


[ 1 ] Bug #2241496 - CVE-2023-43655 composer: Remote Code Execution via web-accessible composer.phar https://bugzilla.redhat.com/show_bug.cgi?id=2241496

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f3dedfef46' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: composer
Product: Fedora 38
Version: 2.6.5
Release: 1.fc38
Summary: Dependency Manager for PHP

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here