Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
100

SUSE: 2022:3957-1 Moderate: php72 Uncontrolled Recursion And Cookie Threats

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3957-1 Rating: moderate References: #1203867 #1203870 Cross-References: CVE-2022-31628 CVE-2022-31629 CVSS scores: CVE-2022-31628 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2022-31628 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVE-2022-31629 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for php72 fixes the following issues: - CVE-2022-31628: Fixed an uncontrolled recursion in the phar uncompressor while decompressing "quines" gzip files. (bsc#1203867) - CVE-2022-31629: Fixed a bug which could lead an attacker to set an insecure cookie that will treated as secure in the victim's browser. (bsc#1203870) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaSTonline_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3957=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2022-3957=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.84.1 php72-debugsource-7.2.5-1.84.1 php72-devel-7.2.5-1.84.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.84.1 apache2-mod_php72-debuginfo-7.2.5-1.84.1 php72-7.2.5-1.84.1 php72-bcmath-7.2.5-1.84.1 php72-bcmath-debuginfo-7.2.5-1.84.1 php72-bz2-7.2.5-1.84.1 php72-bz2-debuginfo-7.2.5-1.84.1 php72-calendar-7.2.5-1.84.1 php72-calendar-debuginfo-7.2.5-1.84.1 php72-ctype-7.2.5-1.84.1 php72-ctype-debuginfo-7.2.5-1.84.1 php72-curl-7.2.5-1.84.1 php72-curl-debuginfo-7.2.5-1.84.1 php72-dba-7.2.5-1.84.1 php72-dba-debuginfo-7.2.5-1.84.1 php72-debuginfo-7.2.5-1.84.1 php72-debugsource-7.2.5-1.84.1 php72-dom-7.2.5-1.84.1 php72-dom-debuginfo-7.2.5-1.84.1 php72-enchant-7.2.5-1.84.1 php72-enchant-debuginfo-7.2.5-1.84.1 php72-exif-7.2.5-1.84.1 php72-exif-debuginfo-7.2.5-1.84.1 php72-fastcgi-7.2.5-1.84.1 php72-fastcgi-debuginfo-7.2.5-1.84.1 php72-fileinfo-7.2.5-1.84.1 php72-fileinfo-debuginfo-7.2.5-1.84.1 php72-fpm-7.2.5-1.84.1 php72-fpm-debuginfo-7.2.5-1.84.1 php72-ftp-7.2.5-1.84.1 php72-ftp-debuginfo-7.2.5-1.84.1 php72-gd-7.2.5-1.84.1 php72-gd-debuginfo-7.2.5-1.84.1 php72-gettext-7.2.5-1.84.1 php72-gettext-debuginfo-7.2.5-1.84.1 php72-gmp-7.2.5-1.84.1 php72-gmp-debuginfo-7.2.5-1.84.1 php72-iconv-7.2.5-1.84.1 php72-iconv-debuginfo-7.2.5-1.84.1 php72-imap-7.2.5-1.84.1 php72-imap-debuginfo-7.2.5-1.84.1 php72-intl-7.2.5-1.84.1 php72-intl-debuginfo-7.2.5-1.84.1 php72-json-7.2.5-1.84.1 php72-json-debuginfo-7.2.5-1.84.1 php72-ldap-7.2.5-1.84.1 php72-ldap-debuginfo-7.2.5-1.84.1 php72-mbstring-7.2.5-1.84.1 php72-mbstring-debuginfo-7.2.5-1.84.1 php72-mysql-7.2.5-1.84.1 php72-mysql-debuginfo-7.2.5-1.84.1 php72-odbc-7.2.5-1.84.1 php72-odbc-debuginfo-7.2.5-1.84.1 php72-opcache-7.2.5-1.84.1 php72-opcache-debuginfo-7.2.5-1.84.1 php72-openssl-7.2.5-1.84.1 php72-openssl-debuginfo-7.2.5-1.84.1 php72-pcntl-7.2.5-1.84.1 php72-pcntl-debuginfo-7.2.5-1.84.1 php72-pdo-7.2.5-1.84.1 php72-pdo-debuginfo-7.2.5-1.84.1 php72-pgsql-7.2.5-1.84.1 php72-pgsql-debuginfo-7.2.5-1.84.1 php72-phar-7.2.5-1.84.1 php72-phar-debuginfo-7.2.5-1.84.1 php72-posix-7.2.5-1.84.1 php72-posix-debuginfo-7.2.5-1.84.1 php72-pspell-7.2.5-1.84.1 php72-pspell-debuginfo-7.2.5-1.84.1 php72-readline-7.2.5-1.84.1 php72-readline-debuginfo-7.2.5-1.84.1 php72-shmop-7.2.5-1.84.1 php72-shmop-debuginfo-7.2.5-1.84.1 php72-snmp-7.2.5-1.84.1 php72-snmp-debuginfo-7.2.5-1.84.1 php72-soap-7.2.5-1.84.1 php72-soap-debuginfo-7.2.5-1.84.1 php72-sockets-7.2.5-1.84.1 php72-sockets-debuginfo-7.2.5-1.84.1 php72-sodium-7.2.5-1.84.1 php72-sodium-debuginfo-7.2.5-1.84.1 php72-sqlite-7.2.5-1.84.1 php72-sqlite-debuginfo-7.2.5-1.84.1 php72-sysvmsg-7.2.5-1.84.1 php72-sysvmsg-debuginfo-7.2.5-1.84.1 php72-sysvsem-7.2.5-1.84.1 php72-sysvsem-debuginfo-7.2.5-1.84.1 php72-sysvshm-7.2.5-1.84.1 php72-sysvshm-debuginfo-7.2.5-1.84.1 php72-tidy-7.2.5-1.84.1 php72-tidy-debuginfo-7.2.5-1.84.1 php72-tokenizer-7.2.5-1.84.1 php72-tokenizer-debuginfo-7.2.5-1.84.1 php72-wddx-7.2.5-1.84.1 php72-wddx-debuginfo-7.2.5-1.84.1 php72-xmlreader-7.2.5-1.84.1 php72-xmlreader-debuginfo-7.2.5-1.84.1 php72-xmlrpc-7.2.5-1.84.1 php72-xmlrpc-debuginfo-7.2.5-1.84.1 php72-xmlwriter-7.2.5-1.84.1 php72-xmlwriter-debuginfo-7.2.5-1.84.1 php72-xsl-7.2.5-1.84.1 php72-xsl-debuginfo-7.2.5-1.84.1 php72-zip-7.2.5-1.84.1 php72-zip-debuginfo-7.2.5-1.84.1 php72-zlib-7.2.5-1.84.1 php72-zlib-debuginfo-7.2.5-1.84.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.84.1 php72-pear-Archive_Tar-7.2.5-1.84.1 References: https://www.suse.com/security/cve/CVE-2022-31628.html https://www.suse.com/security/cve/CVE-2022-31629.html https://bugzilla.suse.com/1203867 https://bugzilla.suse.com/1203870 . The latest patch for php72 resolves two vulnerabilities impacting SUSE environments, as alerted in the advisory SUSE-SU-2022:3957-1, categorized with a moderate severity level.. SUSE PHP Update, Security Fixes, Linux Patch Management, PHP Threats. . LinuxSecurity.com Team

Calendar 2 Nov 11, 2022 SuSE
100

SUSE: 2022:1714-1 Low: php72 Filter Bypass Vulnerability Report

An update that contains security fixes can now be installed. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1714-1 Rating: low References: #1197644 Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for php72 fixes the following issues: - Fixed filter_var bypass vulnerability (bsc#1197644). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-1714=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2022-1714=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.78.1 php72-debugsource-7.2.5-1.78.1 php72-devel-7.2.5-1.78.1 - SUSE Linux Enterprise Module for WebScripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.78.1 apache2-mod_php72-debuginfo-7.2.5-1.78.1 php72-7.2.5-1.78.1 php72-bcmath-7.2.5-1.78.1 php72-bcmath-debuginfo-7.2.5-1.78.1 php72-bz2-7.2.5-1.78.1 php72-bz2-debuginfo-7.2.5-1.78.1 php72-calendar-7.2.5-1.78.1 php72-calendar-debuginfo-7.2.5-1.78.1 php72-ctype-7.2.5-1.78.1 php72-ctype-debuginfo-7.2.5-1.78.1 php72-curl-7.2.5-1.78.1 php72-curl-debuginfo-7.2.5-1.78.1 php72-dba-7.2.5-1.78.1 php72-dba-debuginfo-7.2.5-1.78.1 php72-debuginfo-7.2.5-1.78.1 php72-debugsource-7.2.5-1.78.1 php72-dom-7.2.5-1.78.1 php72-dom-debuginfo-7.2.5-1.78.1 php72-enchant-7.2.5-1.78.1 php72-enchant-debuginfo-7.2.5-1.78.1 php72-exif-7.2.5-1.78.1 php72-exif-debuginfo-7.2.5-1.78.1 php72-fastcgi-7.2.5-1.78.1 php72-fastcgi-debuginfo-7.2.5-1.78.1 php72-fileinfo-7.2.5-1.78.1 php72-fileinfo-debuginfo-7.2.5-1.78.1 php72-fpm-7.2.5-1.78.1 php72-fpm-debuginfo-7.2.5-1.78.1 php72-ftp-7.2.5-1.78.1 php72-ftp-debuginfo-7.2.5-1.78.1 php72-gd-7.2.5-1.78.1 php72-gd-debuginfo-7.2.5-1.78.1 php72-gettext-7.2.5-1.78.1 php72-gettext-debuginfo-7.2.5-1.78.1 php72-gmp-7.2.5-1.78.1 php72-gmp-debuginfo-7.2.5-1.78.1 php72-iconv-7.2.5-1.78.1 php72-iconv-debuginfo-7.2.5-1.78.1 php72-imap-7.2.5-1.78.1 php72-imap-debuginfo-7.2.5-1.78.1 php72-intl-7.2.5-1.78.1 php72-intl-debuginfo-7.2.5-1.78.1 php72-json-7.2.5-1.78.1 php72-json-debuginfo-7.2.5-1.78.1 php72-ldap-7.2.5-1.78.1 php72-ldap-debuginfo-7.2.5-1.78.1 php72-mbstring-7.2.5-1.78.1 php72-mbstring-debuginfo-7.2.5-1.78.1 php72-mysql-7.2.5-1.78.1 php72-mysql-debuginfo-7.2.5-1.78.1 php72-odbc-7.2.5-1.78.1 php72-odbc-debuginfo-7.2.5-1.78.1 php72-opcache-7.2.5-1.78.1 php72-opcache-debuginfo-7.2.5-1.78.1 php72-openssl-7.2.5-1.78.1 php72-openssl-debuginfo-7.2.5-1.78.1 php72-pcntl-7.2.5-1.78.1 php72-pcntl-debuginfo-7.2.5-1.78.1 php72-pdo-7.2.5-1.78.1 php72-pdo-debuginfo-7.2.5-1.78.1 php72-pgsql-7.2.5-1.78.1 php72-pgsql-debuginfo-7.2.5-1.78.1 php72-phar-7.2.5-1.78.1 php72-phar-debuginfo-7.2.5-1.78.1 php72-posix-7.2.5-1.78.1 php72-posix-debuginfo-7.2.5-1.78.1 php72-pspell-7.2.5-1.78.1 php72-pspell-debuginfo-7.2.5-1.78.1 php72-readline-7.2.5-1.78.1 php72-readline-debuginfo-7.2.5-1.78.1 php72-shmop-7.2.5-1.78.1 php72-shmop-debuginfo-7.2.5-1.78.1 php72-snmp-7.2.5-1.78.1 php72-snmp-debuginfo-7.2.5-1.78.1 php72-soap-7.2.5-1.78.1 php72-soap-debuginfo-7.2.5-1.78.1 php72-sockets-7.2.5-1.78.1 php72-sockets-debuginfo-7.2.5-1.78.1 php72-sodium-7.2.5-1.78.1 php72-sodium-debuginfo-7.2.5-1.78.1 php72-sqlite-7.2.5-1.78.1 php72-sqlite-debuginfo-7.2.5-1.78.1 php72-sysvmsg-7.2.5-1.78.1 php72-sysvmsg-debuginfo-7.2.5-1.78.1 php72-sysvsem-7.2.5-1.78.1 php72-sysvsem-debuginfo-7.2.5-1.78.1 php72-sysvshm-7.2.5-1.78.1 php72-sysvshm-debuginfo-7.2.5-1.78.1 php72-tidy-7.2.5-1.78.1 php72-tidy-debuginfo-7.2.5-1.78.1 php72-tokenizer-7.2.5-1.78.1 php72-tokenizer-debuginfo-7.2.5-1.78.1 php72-wddx-7.2.5-1.78.1 php72-wddx-debuginfo-7.2.5-1.78.1 php72-xmlreader-7.2.5-1.78.1 php72-xmlreader-debuginfo-7.2.5-1.78.1 php72-xmlrpc-7.2.5-1.78.1 php72-xmlrpc-debuginfo-7.2.5-1.78.1 php72-xmlwriter-7.2.5-1.78.1 php72-xmlwriter-debuginfo-7.2.5-1.78.1 php72-xsl-7.2.5-1.78.1 php72-xsl-debuginfo-7.2.5-1.78.1 php72-zip-7.2.5-1.78.1 php72-zip-debuginfo-7.2.5-1.78.1 php72-zlib-7.2.5-1.78.1 php72-zlib-debuginfo-7.2.5-1.78.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.78.1 php72-pear-Archive_Tar-7.2.5-1.78.1 References: https://bugzilla.suse.com/1197644 . SUSE Rollout for php72 addresses vulnerabilities in filter_var; apply updates to protect impacted applications.. SUSE Security Update, php72 Patch, Filter Bypass Issue, SUSE Security Fixes. . Severity: Low. LinuxSecurity.com Team

Calendar 2 May 17, 2022 Low SuSE
100

SUSE: 2022:0577-1 Moderate Security Update for php72 DoS Vulnerability

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0577-1 Rating: moderate References: #1038980 #1081790 #1193041 Cross-References: CVE-2015-9253 CVE-2017-8923 CVE-2021-21707 CVSS scores: CVE-2015-9253 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2015-9253 (SUSE): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2017-8923 (NVD) : 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2017-8923 (SUSE): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2021-21707 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2021-21707 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for php72 fixes the following issues: - CVE-2015-9253: Fixed endless loop when the master process restarts a child process using program executionfunctions (bsc#1081790). - CVE-2017-8923: Fixed denial of service (application crash) when using . with a long string (zend_string_extend func in Zend/zend_string.h) (bsc#1038980). - CVE-2021-21707: Fixed special character handling that broke path in xml parsing (bsc#1193041). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-577=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2022-577=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.75.1 php72-debugsource-7.2.5-1.75.1 php72-devel-7.2.5-1.75.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.75.1 apache2-mod_php72-debuginfo-7.2.5-1.75.1 php72-7.2.5-1.75.1 php72-bcmath-7.2.5-1.75.1 php72-bcmath-debuginfo-7.2.5-1.75.1 php72-bz2-7.2.5-1.75.1 php72-bz2-debuginfo-7.2.5-1.75.1 php72-calendar-7.2.5-1.75.1 php72-calendar-debuginfo-7.2.5-1.75.1 php72-ctype-7.2.5-1.75.1 php72-ctype-debuginfo-7.2.5-1.75.1 php72-curl-7.2.5-1.75.1 php72-curl-debuginfo-7.2.5-1.75.1 php72-dba-7.2.5-1.75.1 php72-dba-debuginfo-7.2.5-1.75.1 php72-debuginfo-7.2.5-1.75.1 php72-debugsource-7.2.5-1.75.1 php72-dom-7.2.5-1.75.1 php72-dom-debuginfo-7.2.5-1.75.1 php72-enchant-7.2.5-1.75.1 php72-enchant-debuginfo-7.2.5-1.75.1 php72-exif-7.2.5-1.75.1 php72-exif-debuginfo-7.2.5-1.75.1 php72-fastcgi-7.2.5-1.75.1 php72-fastcgi-debuginfo-7.2.5-1.75.1 php72-fileinfo-7.2.5-1.75.1 php72-fileinfo-debuginfo-7.2.5-1.75.1 php72-fpm-7.2.5-1.75.1 php72-fpm-debuginfo-7.2.5-1.75.1 php72-ftp-7.2.5-1.75.1 php72-ftp-debuginfo-7.2.5-1.75.1 php72-gd-7.2.5-1.75.1 php72-gd-debuginfo-7.2.5-1.75.1 php72-gettext-7.2.5-1.75.1 php72-gettext-debuginfo-7.2.5-1.75.1 php72-gmp-7.2.5-1.75.1 php72-gmp-debuginfo-7.2.5-1.75.1 php72-iconv-7.2.5-1.75.1 php72-iconv-debuginfo-7.2.5-1.75.1 php72-imap-7.2.5-1.75.1 php72-imap-debuginfo-7.2.5-1.75.1 php72-intl-7.2.5-1.75.1 php72-intl-debuginfo-7.2.5-1.75.1 php72-json-7.2.5-1.75.1 php72-json-debuginfo-7.2.5-1.75.1 php72-ldap-7.2.5-1.75.1 php72-ldap-debuginfo-7.2.5-1.75.1 php72-mbstring-7.2.5-1.75.1 php72-mbstring-debuginfo-7.2.5-1.75.1 php72-mysql-7.2.5-1.75.1 php72-mysql-debuginfo-7.2.5-1.75.1 php72-odbc-7.2.5-1.75.1 php72-odbc-debuginfo-7.2.5-1.75.1 php72-opcache-7.2.5-1.75.1 php72-opcache-debuginfo-7.2.5-1.75.1 php72-openssl-7.2.5-1.75.1 php72-openssl-debuginfo-7.2.5-1.75.1 php72-pcntl-7.2.5-1.75.1 php72-pcntl-debuginfo-7.2.5-1.75.1 php72-pdo-7.2.5-1.75.1 php72-pdo-debuginfo-7.2.5-1.75.1 php72-pgsql-7.2.5-1.75.1 php72-pgsql-debuginfo-7.2.5-1.75.1 php72-phar-7.2.5-1.75.1 php72-phar-debuginfo-7.2.5-1.75.1 php72-posix-7.2.5-1.75.1 php72-posix-debuginfo-7.2.5-1.75.1 php72-pspell-7.2.5-1.75.1 php72-pspell-debuginfo-7.2.5-1.75.1 php72-readline-7.2.5-1.75.1 php72-readline-debuginfo-7.2.5-1.75.1 php72-shmop-7.2.5-1.75.1 php72-shmop-debuginfo-7.2.5-1.75.1 php72-snmp-7.2.5-1.75.1 php72-snmp-debuginfo-7.2.5-1.75.1 php72-soap-7.2.5-1.75.1 php72-soap-debuginfo-7.2.5-1.75.1 php72-sockets-7.2.5-1.75.1 php72-sockets-debuginfo-7.2.5-1.75.1 php72-sodium-7.2.5-1.75.1 php72-sodium-debuginfo-7.2.5-1.75.1 php72-sqlite-7.2.5-1.75.1 php72-sqlite-debuginfo-7.2.5-1.75.1 php72-sysvmsg-7.2.5-1.75.1 php72-sysvmsg-debuginfo-7.2.5-1.75.1 php72-sysvsem-7.2.5-1.75.1 php72-sysvsem-debuginfo-7.2.5-1.75.1 php72-sysvshm-7.2.5-1.75.1 php72-sysvshm-debuginfo-7.2.5-1.75.1 php72-tidy-7.2.5-1.75.1 php72-tidy-debuginfo-7.2.5-1.75.1 php72-tokenizer-7.2.5-1.75.1 php72-tokenizer-debuginfo-7.2.5-1.75.1 php72-wddx-7.2.5-1.75.1 php72-wddx-debuginfo-7.2.5-1.75.1 php72-xmlreader-7.2.5-1.75.1 php72-xmlreader-debuginfo-7.2.5-1.75.1 php72-xmlrpc-7.2.5-1.75.1 php72-xmlrpc-debuginfo-7.2.5-1.75.1 php72-xmlwriter-7.2.5-1.75.1 php72-xmlwriter-debuginfo-7.2.5-1.75.1 php72-xsl-7.2.5-1.75.1 php72-xsl-debuginfo-7.2.5-1.75.1 php72-zip-7.2.5-1.75.1 php72-zip-debuginfo-7.2.5-1.75.1 php72-zlib-7.2.5-1.75.1 php72-zlib-debuginfo-7.2.5-1.75.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.75.1 php72-pear-Archive_Tar-7.2.5-1.75.1 References: https://www.suse.com/security/cve/CVE-2015-9253.html https://www.suse.com/security/cve/CVE-2017-8923.html https://www.suse.com/security/cve/CVE-2021-21707.html https://bugzilla.suse.com/1038980 https://bugzilla.suse.com/1081790 https://bugzilla.suse.com/1193041 . SUSE Security Notice: php74 addresses various vulnerabilities. Apply updates immediately if you are using SUSE Linux distributions.. SUSE Security Update, php72, DoS Fix, Security Update Instructions. . LinuxSecurity.com Team

Calendar 2 Feb 25, 2022 SuSE
100

SUSE: 2021:3727-1 Moderate: php72 Local Escalation Threat

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3727-1 Rating: moderate References: #1192050 Cross-References: CVE-2021-21703 CVSS scores: CVE-2021-21703 (NVD) : 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-21703 (SUSE): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php72 fixes the following issues: - CVE-2021-21703: Fixed local privilege escalation via PHP-FPM (bsc#1192050). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-3727=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-3727=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.72.1 php72-debugsource-7.2.5-1.72.1 php72-devel-7.2.5-1.72.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.72.1 apache2-mod_php72-debuginfo-7.2.5-1.72.1 php72-7.2.5-1.72.1 php72-bcmath-7.2.5-1.72.1 php72-bcmath-debuginfo-7.2.5-1.72.1 php72-bz2-7.2.5-1.72.1 php72-bz2-debuginfo-7.2.5-1.72.1 php72-calendar-7.2.5-1.72.1 php72-calendar-debuginfo-7.2.5-1.72.1 php72-ctype-7.2.5-1.72.1 php72-ctype-debuginfo-7.2.5-1.72.1 php72-curl-7.2.5-1.72.1 php72-curl-debuginfo-7.2.5-1.72.1 php72-dba-7.2.5-1.72.1 php72-dba-debuginfo-7.2.5-1.72.1 php72-debuginfo-7.2.5-1.72.1 php72-debugsource-7.2.5-1.72.1 php72-dom-7.2.5-1.72.1 php72-dom-debuginfo-7.2.5-1.72.1 php72-enchant-7.2.5-1.72.1 php72-enchant-debuginfo-7.2.5-1.72.1 php72-exif-7.2.5-1.72.1 php72-exif-debuginfo-7.2.5-1.72.1 php72-fastcgi-7.2.5-1.72.1 php72-fastcgi-debuginfo-7.2.5-1.72.1 php72-fileinfo-7.2.5-1.72.1 php72-fileinfo-debuginfo-7.2.5-1.72.1 php72-fpm-7.2.5-1.72.1 php72-fpm-debuginfo-7.2.5-1.72.1 php72-ftp-7.2.5-1.72.1 php72-ftp-debuginfo-7.2.5-1.72.1 php72-gd-7.2.5-1.72.1 php72-gd-debuginfo-7.2.5-1.72.1 php72-gettext-7.2.5-1.72.1 php72-gettext-debuginfo-7.2.5-1.72.1 php72-gmp-7.2.5-1.72.1 php72-gmp-debuginfo-7.2.5-1.72.1 php72-iconv-7.2.5-1.72.1 php72-iconv-debuginfo-7.2.5-1.72.1 php72-imap-7.2.5-1.72.1 php72-imap-debuginfo-7.2.5-1.72.1 php72-intl-7.2.5-1.72.1 php72-intl-debuginfo-7.2.5-1.72.1 php72-json-7.2.5-1.72.1 php72-json-debuginfo-7.2.5-1.72.1 php72-ldap-7.2.5-1.72.1 php72-ldap-debuginfo-7.2.5-1.72.1 php72-mbstring-7.2.5-1.72.1 php72-mbstring-debuginfo-7.2.5-1.72.1 php72-mysql-7.2.5-1.72.1 php72-mysql-debuginfo-7.2.5-1.72.1 php72-odbc-7.2.5-1.72.1 php72-odbc-debuginfo-7.2.5-1.72.1 php72-opcache-7.2.5-1.72.1 php72-opcache-debuginfo-7.2.5-1.72.1 php72-openssl-7.2.5-1.72.1 php72-openssl-debuginfo-7.2.5-1.72.1 php72-pcntl-7.2.5-1.72.1 php72-pcntl-debuginfo-7.2.5-1.72.1 php72-pdo-7.2.5-1.72.1 php72-pdo-debuginfo-7.2.5-1.72.1 php72-pgsql-7.2.5-1.72.1 php72-pgsql-debuginfo-7.2.5-1.72.1 php72-phar-7.2.5-1.72.1 php72-phar-debuginfo-7.2.5-1.72.1 php72-posix-7.2.5-1.72.1 php72-posix-debuginfo-7.2.5-1.72.1 php72-pspell-7.2.5-1.72.1 php72-pspell-debuginfo-7.2.5-1.72.1 php72-readline-7.2.5-1.72.1 php72-readline-debuginfo-7.2.5-1.72.1 php72-shmop-7.2.5-1.72.1 php72-shmop-debuginfo-7.2.5-1.72.1 php72-snmp-7.2.5-1.72.1 php72-snmp-debuginfo-7.2.5-1.72.1 php72-soap-7.2.5-1.72.1 php72-soap-debuginfo-7.2.5-1.72.1 php72-sockets-7.2.5-1.72.1 php72-sockets-debuginfo-7.2.5-1.72.1 php72-sodium-7.2.5-1.72.1 php72-sodium-debuginfo-7.2.5-1.72.1 php72-sqlite-7.2.5-1.72.1 php72-sqlite-debuginfo-7.2.5-1.72.1 php72-sysvmsg-7.2.5-1.72.1 php72-sysvmsg-debuginfo-7.2.5-1.72.1 php72-sysvsem-7.2.5-1.72.1 php72-sysvsem-debuginfo-7.2.5-1.72.1 php72-sysvshm-7.2.5-1.72.1 php72-sysvshm-debuginfo-7.2.5-1.72.1 php72-tidy-7.2.5-1.72.1 php72-tidy-debuginfo-7.2.5-1.72.1 php72-tokenizer-7.2.5-1.72.1 php72-tokenizer-debuginfo-7.2.5-1.72.1 php72-wddx-7.2.5-1.72.1 php72-wddx-debuginfo-7.2.5-1.72.1 php72-xmlreader-7.2.5-1.72.1 php72-xmlreader-debuginfo-7.2.5-1.72.1 php72-xmlrpc-7.2.5-1.72.1 php72-xmlrpc-debuginfo-7.2.5-1.72.1 php72-xmlwriter-7.2.5-1.72.1 php72-xmlwriter-debuginfo-7.2.5-1.72.1 php72-xsl-7.2.5-1.72.1 php72-xsl-debuginfo-7.2.5-1.72.1 php72-zip-7.2.5-1.72.1 php72-zip-debuginfo-7.2.5-1.72.1 php72-zlib-7.2.5-1.72.1 php72-zlib-debuginfo-7.2.5-1.72.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.72.1 php72-pear-Archive_Tar-7.2.5-1.72.1 References: https://www.suse.com/security/cve/CVE-2021-21703.html https://bugzilla.suse.com/1192050 . The python38 upgrade mitigates a remote code execution vulnerability enhancing protection for Ubuntu clients.. SUSE Security Update, php72 exploit, privilege escalation, software patching, Linux security. . LinuxSecurity.com Team

Calendar 2 Nov 19, 2021 SuSE
100

SUSE: 2021:2926-1 Important: Fix for php72 Directory Traversal

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2926-1 Rating: important References: #1189591 Cross-References: CVE-2020-36193 CVSS scores: CVE-2020-36193 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2020-36193 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php72 fixes the following issues: - CVE-2020-36193: Fixed Archive_Tar directory traversal due to inadequate checking of symbolic links (bsc#1189591). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-2926=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-2926=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.69.1 php72-debugsource-7.2.5-1.69.1 php72-devel-7.2.5-1.69.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.69.1 apache2-mod_php72-debuginfo-7.2.5-1.69.1 php72-7.2.5-1.69.1 php72-bcmath-7.2.5-1.69.1 php72-bcmath-debuginfo-7.2.5-1.69.1 php72-bz2-7.2.5-1.69.1 php72-bz2-debuginfo-7.2.5-1.69.1 php72-calendar-7.2.5-1.69.1 php72-calendar-debuginfo-7.2.5-1.69.1 php72-ctype-7.2.5-1.69.1 php72-ctype-debuginfo-7.2.5-1.69.1 php72-curl-7.2.5-1.69.1 php72-curl-debuginfo-7.2.5-1.69.1 php72-dba-7.2.5-1.69.1 php72-dba-debuginfo-7.2.5-1.69.1 php72-debuginfo-7.2.5-1.69.1 php72-debugsource-7.2.5-1.69.1 php72-dom-7.2.5-1.69.1 php72-dom-debuginfo-7.2.5-1.69.1 php72-enchant-7.2.5-1.69.1 php72-enchant-debuginfo-7.2.5-1.69.1 php72-exif-7.2.5-1.69.1 php72-exif-debuginfo-7.2.5-1.69.1 php72-fastcgi-7.2.5-1.69.1 php72-fastcgi-debuginfo-7.2.5-1.69.1 php72-fileinfo-7.2.5-1.69.1 php72-fileinfo-debuginfo-7.2.5-1.69.1 php72-fpm-7.2.5-1.69.1 php72-fpm-debuginfo-7.2.5-1.69.1 php72-ftp-7.2.5-1.69.1 php72-ftp-debuginfo-7.2.5-1.69.1 php72-gd-7.2.5-1.69.1 php72-gd-debuginfo-7.2.5-1.69.1 php72-gettext-7.2.5-1.69.1 php72-gettext-debuginfo-7.2.5-1.69.1 php72-gmp-7.2.5-1.69.1 php72-gmp-debuginfo-7.2.5-1.69.1 php72-iconv-7.2.5-1.69.1 php72-iconv-debuginfo-7.2.5-1.69.1 php72-imap-7.2.5-1.69.1 php72-imap-debuginfo-7.2.5-1.69.1 php72-intl-7.2.5-1.69.1 php72-intl-debuginfo-7.2.5-1.69.1 php72-json-7.2.5-1.69.1 php72-json-debuginfo-7.2.5-1.69.1 php72-ldap-7.2.5-1.69.1 php72-ldap-debuginfo-7.2.5-1.69.1 php72-mbstring-7.2.5-1.69.1 php72-mbstring-debuginfo-7.2.5-1.69.1 php72-mysql-7.2.5-1.69.1 php72-mysql-debuginfo-7.2.5-1.69.1 php72-odbc-7.2.5-1.69.1 php72-odbc-debuginfo-7.2.5-1.69.1 php72-opcache-7.2.5-1.69.1 php72-opcache-debuginfo-7.2.5-1.69.1 php72-openssl-7.2.5-1.69.1 php72-openssl-debuginfo-7.2.5-1.69.1 php72-pcntl-7.2.5-1.69.1 php72-pcntl-debuginfo-7.2.5-1.69.1 php72-pdo-7.2.5-1.69.1 php72-pdo-debuginfo-7.2.5-1.69.1 php72-pgsql-7.2.5-1.69.1 php72-pgsql-debuginfo-7.2.5-1.69.1 php72-phar-7.2.5-1.69.1 php72-phar-debuginfo-7.2.5-1.69.1 php72-posix-7.2.5-1.69.1 php72-posix-debuginfo-7.2.5-1.69.1 php72-pspell-7.2.5-1.69.1 php72-pspell-debuginfo-7.2.5-1.69.1 php72-readline-7.2.5-1.69.1 php72-readline-debuginfo-7.2.5-1.69.1 php72-shmop-7.2.5-1.69.1 php72-shmop-debuginfo-7.2.5-1.69.1 php72-snmp-7.2.5-1.69.1 php72-snmp-debuginfo-7.2.5-1.69.1 php72-soap-7.2.5-1.69.1 php72-soap-debuginfo-7.2.5-1.69.1 php72-sockets-7.2.5-1.69.1 php72-sockets-debuginfo-7.2.5-1.69.1 php72-sodium-7.2.5-1.69.1 php72-sodium-debuginfo-7.2.5-1.69.1 php72-sqlite-7.2.5-1.69.1 php72-sqlite-debuginfo-7.2.5-1.69.1 php72-sysvmsg-7.2.5-1.69.1 php72-sysvmsg-debuginfo-7.2.5-1.69.1 php72-sysvsem-7.2.5-1.69.1 php72-sysvsem-debuginfo-7.2.5-1.69.1 php72-sysvshm-7.2.5-1.69.1 php72-sysvshm-debuginfo-7.2.5-1.69.1 php72-tidy-7.2.5-1.69.1 php72-tidy-debuginfo-7.2.5-1.69.1 php72-tokenizer-7.2.5-1.69.1 php72-tokenizer-debuginfo-7.2.5-1.69.1 php72-wddx-7.2.5-1.69.1 php72-wddx-debuginfo-7.2.5-1.69.1 php72-xmlreader-7.2.5-1.69.1 php72-xmlreader-debuginfo-7.2.5-1.69.1 php72-xmlrpc-7.2.5-1.69.1 php72-xmlrpc-debuginfo-7.2.5-1.69.1 php72-xmlwriter-7.2.5-1.69.1 php72-xmlwriter-debuginfo-7.2.5-1.69.1 php72-xsl-7.2.5-1.69.1 php72-xsl-debuginfo-7.2.5-1.69.1 php72-zip-7.2.5-1.69.1 php72-zip-debuginfo-7.2.5-1.69.1 php72-zlib-7.2.5-1.69.1 php72-zlib-debuginfo-7.2.5-1.69.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.69.1 php72-pear-Archive_Tar-7.2.5-1.69.1 References: https://www.suse.com/security/cve/CVE-2020-36193.html https://bugzilla.suse.com/1189591 . SUSE Security Patch for python3 addresses critical vulnerabilities. Make sure your servers are protected from remote code execution risks.. php72 Fix, Directory Traversal, SUSE Security Update, Software Update. .Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 02, 2021 Important SuSE
100

SUSE 12-SP5: 2021:2564-1 Moderate Vulnerability: Php72 SSRF Bypass Risk

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2564-1 Rating: moderate References: #1188037 Cross-References: CVE-2021-21705 CVSS scores: CVE-2021-21705 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php72 fixes the following issues: - CVE-2021-21705 [bsc#1188037]: SSRF bypass in FILTER_VALIDATE_URL Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-2564=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-2564=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.63.2 php72-debugsource-7.2.5-1.63.2 php72-devel-7.2.5-1.63.2 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.63.2 apache2-mod_php72-debuginfo-7.2.5-1.63.2 php72-7.2.5-1.63.2 php72-bcmath-7.2.5-1.63.2 php72-bcmath-debuginfo-7.2.5-1.63.2 php72-bz2-7.2.5-1.63.2 php72-bz2-debuginfo-7.2.5-1.63.2 php72-calendar-7.2.5-1.63.2 php72-calendar-debuginfo-7.2.5-1.63.2 php72-ctype-7.2.5-1.63.2 php72-ctype-debuginfo-7.2.5-1.63.2 php72-curl-7.2.5-1.63.2 php72-curl-debuginfo-7.2.5-1.63.2 php72-dba-7.2.5-1.63.2 php72-dba-debuginfo-7.2.5-1.63.2 php72-debuginfo-7.2.5-1.63.2 php72-debugsource-7.2.5-1.63.2 php72-dom-7.2.5-1.63.2 php72-dom-debuginfo-7.2.5-1.63.2 php72-enchant-7.2.5-1.63.2 php72-enchant-debuginfo-7.2.5-1.63.2 php72-exif-7.2.5-1.63.2 php72-exif-debuginfo-7.2.5-1.63.2 php72-fastcgi-7.2.5-1.63.2 php72-fastcgi-debuginfo-7.2.5-1.63.2 php72-fileinfo-7.2.5-1.63.2 php72-fileinfo-debuginfo-7.2.5-1.63.2 php72-fpm-7.2.5-1.63.2 php72-fpm-debuginfo-7.2.5-1.63.2 php72-ftp-7.2.5-1.63.2 php72-ftp-debuginfo-7.2.5-1.63.2 php72-gd-7.2.5-1.63.2 php72-gd-debuginfo-7.2.5-1.63.2 php72-gettext-7.2.5-1.63.2 php72-gettext-debuginfo-7.2.5-1.63.2 php72-gmp-7.2.5-1.63.2 php72-gmp-debuginfo-7.2.5-1.63.2 php72-iconv-7.2.5-1.63.2 php72-iconv-debuginfo-7.2.5-1.63.2 php72-imap-7.2.5-1.63.2 php72-imap-debuginfo-7.2.5-1.63.2 php72-intl-7.2.5-1.63.2 php72-intl-debuginfo-7.2.5-1.63.2 php72-json-7.2.5-1.63.2 php72-json-debuginfo-7.2.5-1.63.2 php72-ldap-7.2.5-1.63.2 php72-ldap-debuginfo-7.2.5-1.63.2 php72-mbstring-7.2.5-1.63.2 php72-mbstring-debuginfo-7.2.5-1.63.2 php72-mysql-7.2.5-1.63.2 php72-mysql-debuginfo-7.2.5-1.63.2 php72-odbc-7.2.5-1.63.2 php72-odbc-debuginfo-7.2.5-1.63.2 php72-opcache-7.2.5-1.63.2 php72-opcache-debuginfo-7.2.5-1.63.2 php72-openssl-7.2.5-1.63.2 php72-openssl-debuginfo-7.2.5-1.63.2 php72-pcntl-7.2.5-1.63.2 php72-pcntl-debuginfo-7.2.5-1.63.2 php72-pdo-7.2.5-1.63.2 php72-pdo-debuginfo-7.2.5-1.63.2 php72-pgsql-7.2.5-1.63.2 php72-pgsql-debuginfo-7.2.5-1.63.2 php72-phar-7.2.5-1.63.2 php72-phar-debuginfo-7.2.5-1.63.2 php72-posix-7.2.5-1.63.2 php72-posix-debuginfo-7.2.5-1.63.2 php72-pspell-7.2.5-1.63.2 php72-pspell-debuginfo-7.2.5-1.63.2 php72-readline-7.2.5-1.63.2 php72-readline-debuginfo-7.2.5-1.63.2 php72-shmop-7.2.5-1.63.2 php72-shmop-debuginfo-7.2.5-1.63.2 php72-snmp-7.2.5-1.63.2 php72-snmp-debuginfo-7.2.5-1.63.2 php72-soap-7.2.5-1.63.2 php72-soap-debuginfo-7.2.5-1.63.2 php72-sockets-7.2.5-1.63.2 php72-sockets-debuginfo-7.2.5-1.63.2 php72-sodium-7.2.5-1.63.2 php72-sodium-debuginfo-7.2.5-1.63.2 php72-sqlite-7.2.5-1.63.2 php72-sqlite-debuginfo-7.2.5-1.63.2 php72-sysvmsg-7.2.5-1.63.2 php72-sysvmsg-debuginfo-7.2.5-1.63.2 php72-sysvsem-7.2.5-1.63.2 php72-sysvsem-debuginfo-7.2.5-1.63.2 php72-sysvshm-7.2.5-1.63.2 php72-sysvshm-debuginfo-7.2.5-1.63.2 php72-tidy-7.2.5-1.63.2 php72-tidy-debuginfo-7.2.5-1.63.2 php72-tokenizer-7.2.5-1.63.2 php72-tokenizer-debuginfo-7.2.5-1.63.2 php72-wddx-7.2.5-1.63.2 php72-wddx-debuginfo-7.2.5-1.63.2 php72-xmlreader-7.2.5-1.63.2 php72-xmlreader-debuginfo-7.2.5-1.63.2 php72-xmlrpc-7.2.5-1.63.2 php72-xmlrpc-debuginfo-7.2.5-1.63.2 php72-xmlwriter-7.2.5-1.63.2 php72-xmlwriter-debuginfo-7.2.5-1.63.2 php72-xsl-7.2.5-1.63.2 php72-xsl-debuginfo-7.2.5-1.63.2 php72-zip-7.2.5-1.63.2 php72-zip-debuginfo-7.2.5-1.63.2 php72-zlib-7.2.5-1.63.2 php72-zlib-debuginfo-7.2.5-1.63.2 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.63.2 php72-pear-Archive_Tar-7.2.5-1.63.2 References: https://www.suse.com/security/cve/CVE-2021-21705.html https://bugzilla.suse.com/1188037 . Ubuntu Security Alert for php7.4 resolves a moderate risk SSRF tampering flaw to protect system stability.. php72 Update,SUSE Linux Security,SUSE Patch Instructions. . LinuxSecurity.com Team

Calendar 2 Jul 29, 2021 SuSE
100

SUSE: 2021:0498-1 Critical: PHP72 Null Pointer Issue Fixed

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0498-1 Rating: important References: #1182049 Cross-References: CVE-2021-21702 CVSS scores: CVE-2021-21702 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php72 fixes the following issues: - CVE-2021-21702 [bsc#1182049]: NULL pointer dereference in SoapClient Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-498=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-498=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.60.1 php72-debugsource-7.2.5-1.60.1 php72-devel-7.2.5-1.60.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.60.1 apache2-mod_php72-debuginfo-7.2.5-1.60.1 php72-7.2.5-1.60.1 php72-bcmath-7.2.5-1.60.1 php72-bcmath-debuginfo-7.2.5-1.60.1 php72-bz2-7.2.5-1.60.1 php72-bz2-debuginfo-7.2.5-1.60.1 php72-calendar-7.2.5-1.60.1 php72-calendar-debuginfo-7.2.5-1.60.1 php72-ctype-7.2.5-1.60.1 php72-ctype-debuginfo-7.2.5-1.60.1 php72-curl-7.2.5-1.60.1 php72-curl-debuginfo-7.2.5-1.60.1 php72-dba-7.2.5-1.60.1 php72-dba-debuginfo-7.2.5-1.60.1 php72-debuginfo-7.2.5-1.60.1 php72-debugsource-7.2.5-1.60.1 php72-dom-7.2.5-1.60.1 php72-dom-debuginfo-7.2.5-1.60.1 php72-enchant-7.2.5-1.60.1 php72-enchant-debuginfo-7.2.5-1.60.1 php72-exif-7.2.5-1.60.1 php72-exif-debuginfo-7.2.5-1.60.1 php72-fastcgi-7.2.5-1.60.1 php72-fastcgi-debuginfo-7.2.5-1.60.1 php72-fileinfo-7.2.5-1.60.1 php72-fileinfo-debuginfo-7.2.5-1.60.1 php72-fpm-7.2.5-1.60.1 php72-fpm-debuginfo-7.2.5-1.60.1 php72-ftp-7.2.5-1.60.1 php72-ftp-debuginfo-7.2.5-1.60.1 php72-gd-7.2.5-1.60.1 php72-gd-debuginfo-7.2.5-1.60.1 php72-gettext-7.2.5-1.60.1 php72-gettext-debuginfo-7.2.5-1.60.1 php72-gmp-7.2.5-1.60.1 php72-gmp-debuginfo-7.2.5-1.60.1 php72-iconv-7.2.5-1.60.1 php72-iconv-debuginfo-7.2.5-1.60.1 php72-imap-7.2.5-1.60.1 php72-imap-debuginfo-7.2.5-1.60.1 php72-intl-7.2.5-1.60.1 php72-intl-debuginfo-7.2.5-1.60.1 php72-json-7.2.5-1.60.1 php72-json-debuginfo-7.2.5-1.60.1 php72-ldap-7.2.5-1.60.1 php72-ldap-debuginfo-7.2.5-1.60.1 php72-mbstring-7.2.5-1.60.1 php72-mbstring-debuginfo-7.2.5-1.60.1 php72-mysql-7.2.5-1.60.1 php72-mysql-debuginfo-7.2.5-1.60.1 php72-odbc-7.2.5-1.60.1 php72-odbc-debuginfo-7.2.5-1.60.1 php72-opcache-7.2.5-1.60.1 php72-opcache-debuginfo-7.2.5-1.60.1 php72-openssl-7.2.5-1.60.1 php72-openssl-debuginfo-7.2.5-1.60.1 php72-pcntl-7.2.5-1.60.1 php72-pcntl-debuginfo-7.2.5-1.60.1 php72-pdo-7.2.5-1.60.1 php72-pdo-debuginfo-7.2.5-1.60.1 php72-pgsql-7.2.5-1.60.1 php72-pgsql-debuginfo-7.2.5-1.60.1 php72-phar-7.2.5-1.60.1 php72-phar-debuginfo-7.2.5-1.60.1 php72-posix-7.2.5-1.60.1 php72-posix-debuginfo-7.2.5-1.60.1 php72-pspell-7.2.5-1.60.1 php72-pspell-debuginfo-7.2.5-1.60.1 php72-readline-7.2.5-1.60.1 php72-readline-debuginfo-7.2.5-1.60.1 php72-shmop-7.2.5-1.60.1 php72-shmop-debuginfo-7.2.5-1.60.1 php72-snmp-7.2.5-1.60.1 php72-snmp-debuginfo-7.2.5-1.60.1 php72-soap-7.2.5-1.60.1 php72-soap-debuginfo-7.2.5-1.60.1 php72-sockets-7.2.5-1.60.1 php72-sockets-debuginfo-7.2.5-1.60.1 php72-sodium-7.2.5-1.60.1 php72-sodium-debuginfo-7.2.5-1.60.1 php72-sqlite-7.2.5-1.60.1 php72-sqlite-debuginfo-7.2.5-1.60.1 php72-sysvmsg-7.2.5-1.60.1 php72-sysvmsg-debuginfo-7.2.5-1.60.1 php72-sysvsem-7.2.5-1.60.1 php72-sysvsem-debuginfo-7.2.5-1.60.1 php72-sysvshm-7.2.5-1.60.1 php72-sysvshm-debuginfo-7.2.5-1.60.1 php72-tidy-7.2.5-1.60.1 php72-tidy-debuginfo-7.2.5-1.60.1 php72-tokenizer-7.2.5-1.60.1 php72-tokenizer-debuginfo-7.2.5-1.60.1 php72-wddx-7.2.5-1.60.1 php72-wddx-debuginfo-7.2.5-1.60.1 php72-xmlreader-7.2.5-1.60.1 php72-xmlreader-debuginfo-7.2.5-1.60.1 php72-xmlrpc-7.2.5-1.60.1 php72-xmlrpc-debuginfo-7.2.5-1.60.1 php72-xmlwriter-7.2.5-1.60.1 php72-xmlwriter-debuginfo-7.2.5-1.60.1 php72-xsl-7.2.5-1.60.1 php72-xsl-debuginfo-7.2.5-1.60.1 php72-zip-7.2.5-1.60.1 php72-zip-debuginfo-7.2.5-1.60.1 php72-zlib-7.2.5-1.60.1 php72-zlib-debuginfo-7.2.5-1.60.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.60.1 php72-pear-Archive_Tar-7.2.5-1.60.1 References: https://www.suse.com/security/cve/CVE-2021-21702.html https://bugzilla.suse.com/1182049 . The recent patch for php72 resolves a significant NULL pointer vulnerability in SUSE environments, bolstering overall system security.. SUSE Update NULL Pointer Security Patch, php72 Security Fix, Critical Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 17, 2021 Critical SuSE
100

SUSE: 2021:0125-1 Moderate: php72 Insufficient Filter Update

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0125-1 Rating: moderate References: #1180706 Cross-References: CVE-2020-7071 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php72 fixes the following issue: - CVE-2020-7071: Fixed an insufficient filter in parse_url() that accepted URLs with invalid userinfo (bsc#1180706). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-125=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-125=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.57.1 php72-debugsource-7.2.5-1.57.1 php72-devel-7.2.5-1.57.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.57.1 apache2-mod_php72-debuginfo-7.2.5-1.57.1 php72-7.2.5-1.57.1 php72-bcmath-7.2.5-1.57.1 php72-bcmath-debuginfo-7.2.5-1.57.1 php72-bz2-7.2.5-1.57.1 php72-bz2-debuginfo-7.2.5-1.57.1 php72-calendar-7.2.5-1.57.1 php72-calendar-debuginfo-7.2.5-1.57.1 php72-ctype-7.2.5-1.57.1 php72-ctype-debuginfo-7.2.5-1.57.1 php72-curl-7.2.5-1.57.1 php72-curl-debuginfo-7.2.5-1.57.1 php72-dba-7.2.5-1.57.1 php72-dba-debuginfo-7.2.5-1.57.1 php72-debuginfo-7.2.5-1.57.1 php72-debugsource-7.2.5-1.57.1 php72-dom-7.2.5-1.57.1 php72-dom-debuginfo-7.2.5-1.57.1 php72-enchant-7.2.5-1.57.1 php72-enchant-debuginfo-7.2.5-1.57.1 php72-exif-7.2.5-1.57.1 php72-exif-debuginfo-7.2.5-1.57.1 php72-fastcgi-7.2.5-1.57.1 php72-fastcgi-debuginfo-7.2.5-1.57.1 php72-fileinfo-7.2.5-1.57.1 php72-fileinfo-debuginfo-7.2.5-1.57.1 php72-fpm-7.2.5-1.57.1 php72-fpm-debuginfo-7.2.5-1.57.1 php72-ftp-7.2.5-1.57.1 php72-ftp-debuginfo-7.2.5-1.57.1 php72-gd-7.2.5-1.57.1 php72-gd-debuginfo-7.2.5-1.57.1 php72-gettext-7.2.5-1.57.1 php72-gettext-debuginfo-7.2.5-1.57.1 php72-gmp-7.2.5-1.57.1 php72-gmp-debuginfo-7.2.5-1.57.1 php72-iconv-7.2.5-1.57.1 php72-iconv-debuginfo-7.2.5-1.57.1 php72-imap-7.2.5-1.57.1 php72-imap-debuginfo-7.2.5-1.57.1 php72-intl-7.2.5-1.57.1 php72-intl-debuginfo-7.2.5-1.57.1 php72-json-7.2.5-1.57.1 php72-json-debuginfo-7.2.5-1.57.1 php72-ldap-7.2.5-1.57.1 php72-ldap-debuginfo-7.2.5-1.57.1 php72-mbstring-7.2.5-1.57.1 php72-mbstring-debuginfo-7.2.5-1.57.1 php72-mysql-7.2.5-1.57.1 php72-mysql-debuginfo-7.2.5-1.57.1 php72-odbc-7.2.5-1.57.1 php72-odbc-debuginfo-7.2.5-1.57.1 php72-opcache-7.2.5-1.57.1 php72-opcache-debuginfo-7.2.5-1.57.1 php72-openssl-7.2.5-1.57.1 php72-openssl-debuginfo-7.2.5-1.57.1 php72-pcntl-7.2.5-1.57.1 php72-pcntl-debuginfo-7.2.5-1.57.1 php72-pdo-7.2.5-1.57.1 php72-pdo-debuginfo-7.2.5-1.57.1 php72-pgsql-7.2.5-1.57.1 php72-pgsql-debuginfo-7.2.5-1.57.1 php72-phar-7.2.5-1.57.1 php72-phar-debuginfo-7.2.5-1.57.1 php72-posix-7.2.5-1.57.1 php72-posix-debuginfo-7.2.5-1.57.1 php72-pspell-7.2.5-1.57.1 php72-pspell-debuginfo-7.2.5-1.57.1 php72-readline-7.2.5-1.57.1 php72-readline-debuginfo-7.2.5-1.57.1 php72-shmop-7.2.5-1.57.1 php72-shmop-debuginfo-7.2.5-1.57.1 php72-snmp-7.2.5-1.57.1 php72-snmp-debuginfo-7.2.5-1.57.1 php72-soap-7.2.5-1.57.1 php72-soap-debuginfo-7.2.5-1.57.1 php72-sockets-7.2.5-1.57.1 php72-sockets-debuginfo-7.2.5-1.57.1 php72-sodium-7.2.5-1.57.1 php72-sodium-debuginfo-7.2.5-1.57.1 php72-sqlite-7.2.5-1.57.1 php72-sqlite-debuginfo-7.2.5-1.57.1 php72-sysvmsg-7.2.5-1.57.1 php72-sysvmsg-debuginfo-7.2.5-1.57.1 php72-sysvsem-7.2.5-1.57.1 php72-sysvsem-debuginfo-7.2.5-1.57.1 php72-sysvshm-7.2.5-1.57.1 php72-sysvshm-debuginfo-7.2.5-1.57.1 php72-tidy-7.2.5-1.57.1 php72-tidy-debuginfo-7.2.5-1.57.1 php72-tokenizer-7.2.5-1.57.1 php72-tokenizer-debuginfo-7.2.5-1.57.1 php72-wddx-7.2.5-1.57.1 php72-wddx-debuginfo-7.2.5-1.57.1 php72-xmlreader-7.2.5-1.57.1 php72-xmlreader-debuginfo-7.2.5-1.57.1 php72-xmlrpc-7.2.5-1.57.1 php72-xmlrpc-debuginfo-7.2.5-1.57.1 php72-xmlwriter-7.2.5-1.57.1 php72-xmlwriter-debuginfo-7.2.5-1.57.1 php72-xsl-7.2.5-1.57.1 php72-xsl-debuginfo-7.2.5-1.57.1 php72-zip-7.2.5-1.57.1 php72-zip-debuginfo-7.2.5-1.57.1 php72-zlib-7.2.5-1.57.1 php72-zlib-debuginfo-7.2.5-1.57.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.57.1 php72-pear-Archive_Tar-7.2.5-1.57.1 References: https://www.suse.com/security/cve/CVE-2020-7071.html https://bugzilla.suse.com/1180706 . SUSE publishes a security patch for php72 addressing a vulnerability related to inadequate filtering. Check the advisory for installation details.. php72 Security Patch,SUSE Update,Moderate Vulnerability Fix,Web Scripting Security,Software Development Kit Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 14, 2021 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here