Alerts This Week
Warning Icon 1 1,179
Alerts This Week
Warning Icon 1 1,179

Ubuntu 19.10, 18.04, 16.04: USN-4330-1 Critical PHP Security Issues

ubuntu
Calendar Grey April 15, 2020
Dist Ubuntu Esm H88
Multiple PHP vulnerabilities patched for Ubuntu 19.10, 18.04, 16.04, and 14.04. Remember to update your installation to mitigate security threats.

Several security issues were fixed in PHP.

Summary

Several security issues were fixed in PHP.

Software Description:

- php7.3: server-side, HTML-embedded scripting language (metapackage)

- php7.2: HTML-embedded scripting language interpreter

- php7.0: HTML-embedded scripting language interpreter

- php5: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled certain file uploads.

An attacker could possibly use this issue to cause a crash.

(CVE-2020-7062)

It was discovered that PHP incorrectly handled certain PHAR archive files.

An attacker could possibly use this issue to access sensitive information.

(CVE-2020-7063)

It was discovered that PHP incorrectly handled certain EXIF files.

An attacker could possibly use this issue to access sensitive information

or cause a crash. (CVE-2020-7064)

It was discovered that PHP incorrectly handled certain UTF strings.

An attacker could possibly use this issue to cause a crash or execute

arbitrary code. This issue only af...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.10:
  libapache2-mod-php7.3           7.3.11-0ubuntu0.19.10.4
  php7.3-cgi                      7.3.11-0ubuntu0.19.10.4
  php7.3-cli                      7.3.11-0ubuntu0.19.10.4
  php7.3-fpm                      7.3.11-0ubuntu0.19.10.4
  php7.3-mbstring                 7.3.11-0ubuntu0.19.10.4

Ubuntu 18.04 LTS:
  libapache2-mod-php7.2           7.2.24-0ubuntu0.18.04.4
  php7.2                          7.2.24-0ubuntu0.18.04.4
  php7.2-cgi                      7.2.24-0ubuntu0.18.04.4
  php7.2-cli                      7.2.24-0ubuntu0.18.04.4
  php7.2-fpm                      7.2.24-0ubuntu0.18.04.4

Ubuntu 16.04 LTS:
  libapache2-mod-php7.0           7.0.33-0ubuntu0.16.04.14
  php7.0-cgi                      7.0.33-0ubuntu0.16.04.14
  php7.0-cli                      7.0.33-0ubuntu0.16.04.14
  php7.0-fpm                      7.0.33-0ubuntu0.16.04.14

Ubuntu 14.04 ESM:
  libapache2-mod-php5             5.5.9+dfsg-1ubuntu4.29+esm11
  php5-cgi                        5.5.9+dfsg-1ubuntu4.29+esm11
  php5-cli                        5.5.9+dfsg-1ubuntu4.29+esm11
  php5-fpm                        5.5.9+dfsg-1ubuntu4.29+esm11

Ubuntu 12.04 ESM:
  libapache2-mod-php5             5.3.10-1ubuntu3.45
  php5-cgi                        5.3.10-1ubuntu3.45
  php5-cli                        5.3.10-1ubuntu3.45
  php5-fpm                        5.3.10-1ubuntu3.45

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4330-1

CVE-2020-7062, CVE-2020-7063, CVE-2020-7064, CVE-2020-7065,

CVE-2020-7066

Severity
critical
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-4330-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here