This update for php8 fixes the following issues:
* CVE-2024-11233: buffer overread when processing input with the
convert.quoted-printable-decode filter. (bsc#1233702)
* CVE-2024-11234: possible CRLF injection in URIs when a proxy is configured
in a stream context. (bsc#1233703)
* CVE-2024-8929: data exposure on MySQL clients due to heap buffer overread in
mysqlnd. (bsc#1233651)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2024-4215=1
* openSUSE Leap 15.5
zypper in -t patch openSUSE-SLE-15.5-2024-4215=1
* Web and Scripting Module 15-SP5
zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP5-2024-4215=1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* php8-mbstring-debuginfo-8.0.30-150400.4.49.1
* php8-gmp-8.0.30-150400.4.49.1
* php8-gmp-debuginfo-8.0.30-150400.4.49.1
* php8-sqlite-8.0.30-150400.4.49.1
* php8-ctype-debuginfo-8.0.30-150400.4.49.1
* php8-gettext-debuginfo-8.0.30-150400.4.49.1
* php8-iconv-debuginfo-8.0.30-150400.4.49.1
* php8-dom-8.0.30-150400.4.49.1
* php8-mysql-debuginfo-8.0.30-150400.4.49.1
* php8-intl-debuginfo-8.0.30-150400.4.49.1
* php8-zip-8.0.30-150400.4.49.1
* php8-ftp-debuginfo-8.0.30-150400.4.49.1
* php8-soap-debuginfo-8.0.30-150400.4.49.1
* php8-ctype-8.0.30-150400.4.49.1
* php8-curl-debuginfo-8.0.30-150400.4.49.1
* php8-sysvmsg-debuginfo-8.0.30-150400.4.49.1
* php8-tidy-debuginfo-8.0.30-150400.4.49.1
* php8-fpm-debuginfo-8.0.30-150400.4.49.1
* php8-mbstring-8.0.30-150400.4.49.1
* php8-snmp-8.0.30-150400.4.49.1
* php8-fpm-8.0.30-150400.4.49.1
* php8-xmlreader-debuginfo-8.0.30-150400.4.49.1
* php8-sysvshm-8.0.30-150400.4.49.1
* php8-readline-8.0.30-150400.4.49.1
*...
Read the Full Advisory* bsc#1233651
* bsc#1233702
* bsc#1233703
## References:
* https://www.suse.com/security/cve/CVE-2024-11233.html
* https://www.suse.com/security/cve/CVE-2024-11234.html
* https://www.suse.com/security/cve/CVE-2024-8929.html
* https://bugzilla.suse.com/show_bug.cgi?id=1233651
* https://bugzilla.suse.com/show_bug.cgi?id=1233702
* https://bugzilla.suse.com/show_bug.cgi?id=1233703
Get the latest Linux and open source security news straight to your inbox.