Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for php8 fixes the following issues:
- Updated to version 8.0.27:
- CVE-2022-31631: Fixed an issue where PDO::quote would return an
unquoted string (bsc#1206958).
Non-security fixes:
- Fixed a NULL pointer dereference with -w/-s options.
- Fixed a crash in Generator when interrupted during argument evaluation
with extra named params.
- Fixed a crash in Generator when memory limit was exceeded during
initialization.
- Fixed a memory leak in Generator when interrupted during argument
evaluation.
- Fixed an issue in the DateTimeZone constructor where an extra null
byte could be added to the input.
- Fixed a hang in SaltStack when using php-fpm 8.1.11.
- Fixed mysqli_query warnings being shown despite using silenced error
mode.
- Fixed a NULL pointer dereference when serializing a SOAP response call.
Patch Instructions:
To install this SUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.4:
zypper in -t patch openSUSE-SLE-15.4-2023-74=1
- SUSE Linux Enterprise Module for Web Scripting 15-SP4:
zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP4-2023-74=1
- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):
apache2-mod_php8-8.0.27-150400.4.23.1
apache2-mod_php8-debuginfo-8.0.27-150400.4.23.1
apache2-mod_php8-debugsource-8.0.27-150400.4.23.1
php8-8.0.27-150400.4.23.1
php8-bcmath-8.0.27-150400.4.23.1
php8-bcmath-debuginfo-8.0.27-150400.4.23.1
php8-bz2-8.0.27-150400.4.23.1
php8-bz2-debuginfo-8.0.27-150400.4.23.1
php8-calendar-8.0.27-150400.4.23.1
php8-calendar-debuginfo-8.0.27-150400.4.23.1
php8-cli-8.0.27-150400.4.23.1
php8-cli-debuginfo-8.0.27-150400.4.23.1
php8-ctype-8.0.27-150400.4.23.1
php8-ctype-debuginfo-8.0.27-150400.4.23.1
php8-curl-8.0.27-150400.4.23.1
php8-curl-debuginfo-8.0.27-150400.4.23.1
php8-dba-8.0.27-150400.4.23.1
php8-dba-debuginfo-8.0.27-150400.4.23.1
php8-debuginfo-8.0.27-150400.4.23.1
php8-debugsource-8.0.27-150400.4.23.1
php8-devel-8.0.27-150400.4.23.1
php8-dom-8.0.27-150400.4.23.1
php8-dom-debuginfo-8.0.27-150400.4.23.1
php8-embed-8.0.27-150400.4.23.1
php8-embed-debuginfo-8.0.27-150400.4.23.1
php8-embed-debugsource-8.0.27-150400.4.23.1
php8-e...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2022-31631.html
https://bugzilla.suse.com/1206958
Get the latest Linux and open source security news straight to your inbox.