This update for php7 fixes the following issues:
* CVE-2023-3247: Fixed missing error check and insufficient random bytes in
HTTP Digest authentication for SOAP (bsc#1212349).
## Patch Instructions:
To install this SUSE Moderate update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Manager Server 4.2
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-2980=1
* openSUSE Leap 15.4
zypper in -t patch openSUSE-SLE-15.4-2023-2980=1
* SUSE Manager Server 4.2 (ppc64le s390x x86_64)
* php7-mysql-7.4.33-150200.3.57.1
* php7-odbc-7.4.33-150200.3.57.1
* php7-fastcgi-debuginfo-7.4.33-150200.3.57.1
* php7-ldap-debuginfo-7.4.33-150200.3.57.1
* php7-debugsource-7.4.33-150200.3.57.1
* php7-xmlreader-7.4.33-150200.3.57.1
* php7-enchant-debuginfo-7.4.33-150200.3.57.1
* php7-enchant-7.4.33-150200.3.57.1
* php7-mbstring-7.4.33-150200.3.57.1
* php7-mysql-debuginfo-7.4.33-150200.3.57.1
* php7-sqlite-debuginfo-7.4.33-150200.3.57.1
* php7-dba-debuginfo-7.4.33-150200.3.57.1
* php7-7.4.33-150200.3.57.1
* php7-xmlrpc-7.4.33-150200.3.57.1
* php7-ctype-7.4.33-150200.3.57.1
* php7-intl-debuginfo-7.4.33-150200.3.57.1
* php7-sysvmsg-debuginfo-7.4.33-150200.3.57.1
* php7-sockets-7.4.33-150200.3.57.1
* php7-gmp-7.4.33-150200.3.57.1
* php7-phar-debuginfo-7.4.33-150200.3.57.1
* php7-bz2-debuginfo-7.4.33-150200.3.57.1
* php7-iconv-7.4.33-150200.3.57.1
* php7-calendar-debuginfo-7.4.33-150200.3.57.1
* php7-pdo-7.4.33-150200.3.57.1
* php7-sqlite-7.4.33-150200.3.57.1
*...
Read the Full Advisory* #1212349
## References:
* https://www.suse.com/security/cve/CVE-2023-3247.html
* https://bugzilla.suse.com/show_bug.cgi?id=1212349
Get the latest Linux and open source security news straight to your inbox.