Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2022:4067-1 Important: php7 Critical Buffer Overflow

suse
Calendar Grey November 18, 2022
Scroller Suse
SUSE Security Update for php8 addresses 45 security issues and introduces an enhancement alongside essential updates.
An update that fixes 52 vulnerabilities, contains one feature is now available

Summary

This update for php7 fixes the following issues: - Version update to 7.2.34 [jsc#SLE-23639] - CVE-2022-37454: Fixed SHA-3 buffer overflow (bsc#1204577). - Fix integer overflow in PHP_SHA3##bits (bsc#1204577#c26). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-4067=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-4067=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2022-4067=1 - SUSE Linux Enterprise Server 15-SP1-LTSS:

References

#1204577 SLE-23639

Cross- CVE-2015-9253 CVE-2017-8923 CVE-2017-9120

CVE-2018-1000222 CVE-2018-12882 CVE-2018-14851

CVE-2018-17082 CVE-2018-19935 CVE-2018-20783

CVE-2019-11034 CVE-2019-11035 CVE-2019-11036

CVE-2019-11039 CVE-2019-11040 CVE-2019-11041

CVE-2019-11042 CVE-2019-11043 CVE-2019-11045

CVE-2019-11046 CVE-2019-11047 CVE-2019-11048

CVE-2019-11050 CVE-2019-9020 CVE-2019-9021

CVE-2019-9022 CVE-2019-9023 CVE-2019-9024

CVE-2019-9637 CVE-2019-9638 CVE-2019-9640

CVE-2019-9641 CVE-2019-9675 CVE-2020-7059

CVE-2020-7060 CVE-2020-7062 CVE-2020-7063

CVE-2020-7064 CVE-2020-7066 CVE-2020-7068

CVE-2020-7069 CVE-2020-7070 CVE-2020-7071

CVE-2021-21702 CVE-2021-21703 CVE-2021-21704

CVE-2021-21705 CVE-20...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:4067-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.