Several security issues were fixed in PHP.. =========================================================================Ubuntu Security Notice USN-4583-2 October 27, 2020 php7.4 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 Summary: Several security issues were fixed in PHP. Software Description: - php7.4: server-side, HTML-embedded scripting language (metapackage) Details: USN-4583-1 fixed vulnerabilities in PHP. This update provides the corresponding update for Ubuntu 20.10. Original advisory details: It was discovered that PHP incorrectly handled certain encrypt ciphers. An attacker could possibly use this issue to decrease security or cause incorrect encryption data. (CVE-2020-7069) It was discorevered that PHP incorrectly handled certain HTTP cookies. An attacker could possibly use this issue to forge cookie which is supposed to be secure. (CVE-2020-7070) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: libapache2-mod-php7.4 7.4.9-1ubuntu1.1 php7.4-cgi 7.4.9-1ubuntu1.1 php7.4-cli 7.4.9-1ubuntu1.1 php7.4-curl 7.4.9-1ubuntu1.1 php7.4-fpm 7.4.9-1ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4583-2 https://ubuntu.com/security/notices/USN-4583-1 CVE-2020-7069, CVE-2020-7070 Package Information: https://launchpad.net/ubuntu/+source/php7.4/7.4.9-1ubuntu1.1 . Ubuntu Security Alert USN-4590-1 addresses significant security patches for PHP weaknesses impacting Ubuntu 21.04.. php vulnerabilities, ubuntu security, php7.4 update, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team
PHP contains several vulnerabilities including a heap buffer overflow, potentially leading to the remote execution of arbitrary code under certain conditions. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200703-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: PHP: Multiple vulnerabilities Date: March 20, 2007 Bugs: #153911 ID: 200703-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= PHP contains several vulnerabilities including a heap buffer overflow, potentially leading to the remote execution of arbitrary code under certain conditions. Background ========= PHP is a widely-used general-purpose scripting language that is especially suited for Web development and can be embedded into HTML. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-lang/php < 5.2.1-r3 > = 5.2.1-r3 *> = 5.1.6-r11 *> = 4.4.6 Description ========== Several vulnerabilities were found in PHP by the Hardened-PHP Project and other researchers. These vulnerabilities include a heap-based buffer overflow in htmlentities() and htmlspecialchars() if called with UTF-8 parameters, and an off-by-one error in str_ireplace(). Other vulnerabilities were also found in the PHP4 branch, including possible overflows, stack corruptions and a format string vulnerability in the *print() functions on 64 bit systems. Impact ===== Remote attackersmight be able to exploit these issues in PHP applications making use of the affected functions, potentially resulting in the execution of arbitrary code, Denial of Service, execution of scripted contents in the context of the affected site, security bypass or information leak. Workaround ========= There is no known workaround at this time. Resolution ========= All PHP users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "dev-lang/php" References ========= [ 1 ] CVE-2006-5465 https://www.cve.org/CVERecord?id=CVE-2006-5465 [ 2 ] CVE-2007-0906 https://www.cve.org/CVERecord?id=CVE-2007-0906 [ 3 ] CVE-2007-0907 https://www.cve.org/CVERecord?id=CVE-2007-0907 [ 4 ] CVE-2007-0908 https://www.cve.org/CVERecord?id=CVE-2007-0908 [ 5 ] CVE-2007-0909 https://www.cve.org/CVERecord?id=CVE-2007-0909 [ 6 ] CVE-2007-0910 https://www.cve.org/CVERecord?id=CVE-2007-0910 [ 7 ] CVE-2007-0911 https://www.cve.org/CVERecord?id=CVE-2007-0911 [ 8 ] CVE-2007-0988 https://www.cve.org/CVERecord?id=CVE-2007-0988 [ 9 ] CVE-2007-1286 https://www.cve.org/CVERecord?id=CVE-2007-1286 [ 10 ] CVE-2007-1375 https://www.cve.org/CVERecord?id=CVE-2007-1375 [ 11 ] CVE-2007-1376 https://www.cve.org/CVERecord?id=CVE-2007-1376 [ 12 ] CVE-2007-1380 https://www.cve.org/CVERecord?id=CVE-2007-1380 [ 13 ] CVE-2007-1383 https://www.cve.org/CVERecord?id=CVE-2007-1383 [ 14 ] PHP 4.4.5 Release Announcement https://www.php.net/releases/4_4_5.php [ 15 ] PHP 5.2.1 Release Announcement https://www.php.net/releases/5_2_1.php Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200703-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concernsshould be addressed to
Get the latest Linux and open source security news straight to your inbox.