Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 16.04 ESM: USN-5905-1 Critical PHP Denial Of Service Threat

ubuntu
Calendar Grey March 2, 2023
Scroller Ubuntu
Various vulnerabilities in PHP have been resolved in Ubuntu 16.04 ESM. Urgent updates released for improved security measures.
Several security issues were fixed in PHP.

Summary

Several security issues were fixed in PHP.

Software Description:

- php7.0: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled certain gzip files.

An attacker could possibly use this issue to cause a denial of service.

(CVE-2022-31628)

It was discovered that PHP incorrectly handled certain cookies.

An attacker could possibly use this issue to compromise data integrity.

(CVE-2022-31629)

It was discovered that PHP incorrectly handled certain inputs.

An attacker could possibly use this issue to cause a crash or

execute arbitrary code. (CVE-2022-31631)

It was discovered that PHP incorrectly handled resolving long paths. A

remote attacker could possibly use this issue to obtain or modify sensitive

information. (CVE-2023-0568)

It was discovered that PHP incorrectly handled a large number of field

and file

parts in HTTP form uploads. A remote attacker could possibly use this

issue to

cause PHP to consume...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
   libapache2-mod-php7.0           7.0.33-0ubuntu0.16.04.16+esm5
   php7.0 7.0.33-0ubuntu0.16.04.16+esm5
   php7.0-cgi 7.0.33-0ubuntu0.16.04.16+esm5
   php7.0-cli 7.0.33-0ubuntu0.16.04.16+esm5
   php7.0-fpm 7.0.33-0ubuntu0.16.04.16+esm5
   php7.0-sqlite3 7.0.33-0ubuntu0.16.04.16+esm5
   php7.0-zip 7.0.33-0ubuntu0.16.04.16+esm5

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5905-1

  CVE-2022-31628, CVE-2022-31629, CVE-2022-31631, CVE-2023-0568,

  CVE-2023-0662

Severity
critical
Lowest
Low
Medium
High
Critical

March 02, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.