Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
100

SUSE: 2024:1445-1 Moderate: PHP74 Critical Security Fix Advisory

* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756 . # Security update for php74 Announcement ID: SUSE-SU-2024:1445-1 Rating: moderate References: * bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756 * CVE-2024-3096 CVSS scores: * CVE-2024-2756 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2024-3096 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * Web and Scripting Module 12 An update that solves two vulnerabilities can now be installed. ## Description: This update for php74 fixes the following issues: * CVE-2024-2756: Fixed bypass of security fix applied for CVE-2022-31629 that lead PHP to consider not secure cookies as secure (bsc#1222857) * CVE-2024-3096: Fixed bypass on null byte leading passwords checked via password_verify (bsc#1222858) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 12 zypper in -t patchSUSE-SLE-Module-Web-Scripting-12-2024-1445=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1445=1 ## Package List: * Web and Scripting Module 12 (aarch64 ppc64le s390x x86_64) * php74-7.4.33-1.65.1 * php74-tokenizer-debuginfo-7.4.33-1.65.1 * php74-shmop-debuginfo-7.4.33-1.65.1 * php74-ctype-7.4.33-1.65.1 * php74-calendar-debuginfo-7.4.33-1.65.1 * php74-debugsource-7.4.33-1.65.1 * php74-snmp-7.4.33-1.65.1 * php74-ftp-7.4.33-1.65.1 * php74-xmlreader-debuginfo-7.4.33-1.65.1 * php74-zlib-7.4.33-1.65.1 * php74-opcache-7.4.33-1.65.1 * php74-fpm-7.4.33-1.65.1 * php74-pcntl-debuginfo-7.4.33-1.65.1 * php74-bcmath-7.4.33-1.65.1 * php74-dba-7.4.33-1.65.1 * php74-fastcgi-debuginfo-7.4.33-1.65.1 * php74-xmlwriter-debuginfo-7.4.33-1.65.1 * php74-iconv-7.4.33-1.65.1 * php74-sockets-7.4.33-1.65.1 * php74-gettext-7.4.33-1.65.1 * php74-odbc-7.4.33-1.65.1 * php74-dba-debuginfo-7.4.33-1.65.1 * php74-sysvshm-debuginfo-7.4.33-1.65.1 * php74-snmp-debuginfo-7.4.33-1.65.1 * php74-zip-7.4.33-1.65.1 * php74-soap-debuginfo-7.4.33-1.65.1 * php74-xmlrpc-debuginfo-7.4.33-1.65.1 * php74-posix-7.4.33-1.65.1 * php74-mysql-7.4.33-1.65.1 * php74-curl-7.4.33-1.65.1 * php74-shmop-7.4.33-1.65.1 * php74-fileinfo-7.4.33-1.65.1 * php74-pcntl-7.4.33-1.65.1 * php74-pgsql-debuginfo-7.4.33-1.65.1 * php74-tokenizer-7.4.33-1.65.1 * php74-enchant-debuginfo-7.4.33-1.65.1 * php74-bz2-7.4.33-1.65.1 * php74-ftp-debuginfo-7.4.33-1.65.1 * php74-pdo-debuginfo-7.4.33-1.65.1 * php74-mbstring-7.4.33-1.65.1 * php74-soap-7.4.33-1.65.1 * php74-iconv-debuginfo-7.4.33-1.65.1 * php74-exif-7.4.33-1.65.1 * php74-sysvmsg-7.4.33-1.65.1 * php74-readline-7.4.33-1.65.1 * php74-xmlrpc-7.4.33-1.65.1 * php74-xsl-7.4.33-1.65.1 * php74-bcmath-debuginfo-7.4.33-1.65.1 * php74-sysvshm-7.4.33-1.65.1 *php74-calendar-7.4.33-1.65.1 * php74-fpm-debuginfo-7.4.33-1.65.1 * php74-ldap-7.4.33-1.65.1 * php74-xmlreader-7.4.33-1.65.1 * php74-sysvmsg-debuginfo-7.4.33-1.65.1 * php74-phar-7.4.33-1.65.1 * php74-dom-debuginfo-7.4.33-1.65.1 * php74-sysvsem-7.4.33-1.65.1 * php74-ctype-debuginfo-7.4.33-1.65.1 * php74-sockets-debuginfo-7.4.33-1.65.1 * php74-sqlite-7.4.33-1.65.1 * php74-openssl-7.4.33-1.65.1 * php74-pdo-7.4.33-1.65.1 * php74-enchant-7.4.33-1.65.1 * php74-posix-debuginfo-7.4.33-1.65.1 * php74-zip-debuginfo-7.4.33-1.65.1 * php74-zlib-debuginfo-7.4.33-1.65.1 * php74-xsl-debuginfo-7.4.33-1.65.1 * php74-json-7.4.33-1.65.1 * php74-odbc-debuginfo-7.4.33-1.65.1 * php74-exif-debuginfo-7.4.33-1.65.1 * php74-fastcgi-7.4.33-1.65.1 * php74-gettext-debuginfo-7.4.33-1.65.1 * php74-sqlite-debuginfo-7.4.33-1.65.1 * php74-sysvsem-debuginfo-7.4.33-1.65.1 * php74-pgsql-7.4.33-1.65.1 * php74-debuginfo-7.4.33-1.65.1 * php74-phar-debuginfo-7.4.33-1.65.1 * php74-readline-debuginfo-7.4.33-1.65.1 * php74-sodium-7.4.33-1.65.1 * php74-gmp-debuginfo-7.4.33-1.65.1 * php74-intl-debuginfo-7.4.33-1.65.1 * php74-bz2-debuginfo-7.4.33-1.65.1 * php74-tidy-7.4.33-1.65.1 * php74-gd-7.4.33-1.65.1 * php74-sodium-debuginfo-7.4.33-1.65.1 * php74-tidy-debuginfo-7.4.33-1.65.1 * php74-mysql-debuginfo-7.4.33-1.65.1 * php74-curl-debuginfo-7.4.33-1.65.1 * php74-gmp-7.4.33-1.65.1 * php74-openssl-debuginfo-7.4.33-1.65.1 * php74-xmlwriter-7.4.33-1.65.1 * apache2-mod_php74-7.4.33-1.65.1 * php74-gd-debuginfo-7.4.33-1.65.1 * php74-json-debuginfo-7.4.33-1.65.1 * php74-intl-7.4.33-1.65.1 * php74-dom-7.4.33-1.65.1 * php74-opcache-debuginfo-7.4.33-1.65.1 * apache2-mod_php74-debuginfo-7.4.33-1.65.1 * php74-ldap-debuginfo-7.4.33-1.65.1 * php74-mbstring-debuginfo-7.4.33-1.65.1 * php74-fileinfo-debuginfo-7.4.33-1.65.1 * SUSE Linux Enterprise Software Development Kit 12 SP5(aarch64 ppc64le s390x x86_64) * php74-devel-7.4.33-1.65.1 * php74-debugsource-7.4.33-1.65.1 * php74-debuginfo-7.4.33-1.65.1 ## References: * https://www.suse.com/security/cve/CVE-2024-2756.html * https://www.suse.com/security/cve/CVE-2024-3096.html * https://bugzilla.suse.com/show_bug.cgi?id=1222857 * https://bugzilla.suse.com/show_bug.cgi?id=1222858 . Software patches for php74 aimed at mitigating vulnerabilities CVE-2024-2756 and CVE-2024-3096 to strengthen overall security.. php74 Security Update,SUSE Advisory,CVE-2024-2756,System Patch,PHP Vulnerability. . LinuxSecurity.com Team

Calendar 2 Apr 26, 2024 SuSE
100

SUSE: 2022:4068-1 Important: Fix for PHP74 Buffer Overflow Issue

An update that fixes 18 vulnerabilities, contains one feature is now available. . SUSE Security Update: Security update for php74 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4068-1 Rating: important References: #1203867 #1203870 #1204577 #1204979 SLE-23639 Cross-References: CVE-2017-8923 CVE-2020-7068 CVE-2020-7069 CVE-2020-7070 CVE-2020-7071 CVE-2021-21702 CVE-2021-21703 CVE-2021-21704 CVE-2021-21705 CVE-2021-21706 CVE-2021-21707 CVE-2021-21708 CVE-2022-31625 CVE-2022-31626 CVE-2022-31628 CVE-2022-31629 CVE-2022-31630 CVE-2022-37454 CVSS scores: CVE-2017-8923 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2017-8923 (SUSE): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2020-7068 (NVD) : 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L CVE-2020-7068 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2020-7069 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVE-2020-7069 (SUSE): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2020-7070 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2020-7070 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N CVE-2020-7071 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2020-7071 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2021-21702 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-21702 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-21703 (NVD) : 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-21703 (SUSE): 6.4CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-21704 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-21704 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-21705 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2021-21705 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2021-21706 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVE-2021-21707 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2021-21707 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2021-21708 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-21708 (SUSE): 7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H CVE-2022-31625 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-31625 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-31626 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-31626 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-31628 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2022-31628 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVE-2022-31629 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVE-2022-31630 (NVD) : 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVE-2022-31630 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2022-37454 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-37454 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes 18 vulnerabilities, contains one feature is now available. Description: This update for php74 fixes the following issues: - Version update to 7.4.33: - CVE-2022-31630: Fixed out-of-bounds read due to insufficient input validation in imageloadfont() (bsc#1204979). - CVE-2022-37454: Fixed buffer overflow in hash_update() on long parameter (bsc#1204577). - Version update to 7.4.32 (jsc#SLE-23639) - CVE-2022-31628: Fixed an uncontrolled recursion in the phar uncompressor while decompressing "quines" gzip files. (bsc#1203867) - CVE-2022-31629: Fixed a bug which could lead an attacker to set an insecure cookie that will treated as secure in the victim's browser. (bsc#1203870) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-4068=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2022-4068=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php74-debuginfo-7.4.33-1.47.2 php74-debugsource-7.4.33-1.47.2 php74-devel-7.4.33-1.47.2 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php74-7.4.33-1.47.2 apache2-mod_php74-debuginfo-7.4.33-1.47.2 php74-7.4.33-1.47.2 php74-bcmath-7.4.33-1.47.2 php74-bcmath-debuginfo-7.4.33-1.47.2 php74-bz2-7.4.33-1.47.2 php74-bz2-debuginfo-7.4.33-1.47.2 php74-calendar-7.4.33-1.47.2 php74-calendar-debuginfo-7.4.33-1.47.2 php74-ctype-7.4.33-1.47.2 php74-ctype-debuginfo-7.4.33-1.47.2 php74-curl-7.4.33-1.47.2 php74-curl-debuginfo-7.4.33-1.47.2 php74-dba-7.4.33-1.47.2 php74-dba-debuginfo-7.4.33-1.47.2 php74-debuginfo-7.4.33-1.47.2 php74-debugsource-7.4.33-1.47.2 php74-dom-7.4.33-1.47.2 php74-dom-debuginfo-7.4.33-1.47.2 php74-enchant-7.4.33-1.47.2 php74-enchant-debuginfo-7.4.33-1.47.2 php74-exif-7.4.33-1.47.2 php74-exif-debuginfo-7.4.33-1.47.2 php74-fastcgi-7.4.33-1.47.2 php74-fastcgi-debuginfo-7.4.33-1.47.2 php74-fileinfo-7.4.33-1.47.2 php74-fileinfo-debuginfo-7.4.33-1.47.2 php74-fpm-7.4.33-1.47.2 php74-fpm-debuginfo-7.4.33-1.47.2 php74-ftp-7.4.33-1.47.2 php74-ftp-debuginfo-7.4.33-1.47.2 php74-gd-7.4.33-1.47.2 php74-gd-debuginfo-7.4.33-1.47.2 php74-gettext-7.4.33-1.47.2 php74-gettext-debuginfo-7.4.33-1.47.2 php74-gmp-7.4.33-1.47.2 php74-gmp-debuginfo-7.4.33-1.47.2 php74-iconv-7.4.33-1.47.2 php74-iconv-debuginfo-7.4.33-1.47.2 php74-intl-7.4.33-1.47.2 php74-intl-debuginfo-7.4.33-1.47.2 php74-json-7.4.33-1.47.2 php74-json-debuginfo-7.4.33-1.47.2 php74-ldap-7.4.33-1.47.2 php74-ldap-debuginfo-7.4.33-1.47.2 php74-mbstring-7.4.33-1.47.2 php74-mbstring-debuginfo-7.4.33-1.47.2 php74-mysql-7.4.33-1.47.2 php74-mysql-debuginfo-7.4.33-1.47.2 php74-odbc-7.4.33-1.47.2 php74-odbc-debuginfo-7.4.33-1.47.2 php74-opcache-7.4.33-1.47.2 php74-opcache-debuginfo-7.4.33-1.47.2 php74-openssl-7.4.33-1.47.2 php74-openssl-debuginfo-7.4.33-1.47.2 php74-pcntl-7.4.33-1.47.2 php74-pcntl-debuginfo-7.4.33-1.47.2 php74-pdo-7.4.33-1.47.2 php74-pdo-debuginfo-7.4.33-1.47.2 php74-pgsql-7.4.33-1.47.2 php74-pgsql-debuginfo-7.4.33-1.47.2 php74-phar-7.4.33-1.47.2 php74-phar-debuginfo-7.4.33-1.47.2 php74-posix-7.4.33-1.47.2 php74-posix-debuginfo-7.4.33-1.47.2 php74-readline-7.4.33-1.47.2 php74-readline-debuginfo-7.4.33-1.47.2 php74-shmop-7.4.33-1.47.2 php74-shmop-debuginfo-7.4.33-1.47.2 php74-snmp-7.4.33-1.47.2 php74-snmp-debuginfo-7.4.33-1.47.2 php74-soap-7.4.33-1.47.2 php74-soap-debuginfo-7.4.33-1.47.2 php74-sockets-7.4.33-1.47.2 php74-sockets-debuginfo-7.4.33-1.47.2 php74-sodium-7.4.33-1.47.2 php74-sodium-debuginfo-7.4.33-1.47.2 php74-sqlite-7.4.33-1.47.2 php74-sqlite-debuginfo-7.4.33-1.47.2 php74-sysvmsg-7.4.33-1.47.2 php74-sysvmsg-debuginfo-7.4.33-1.47.2 php74-sysvsem-7.4.33-1.47.2 php74-sysvsem-debuginfo-7.4.33-1.47.2 php74-sysvshm-7.4.33-1.47.2 php74-sysvshm-debuginfo-7.4.33-1.47.2 php74-tidy-7.4.33-1.47.2 php74-tidy-debuginfo-7.4.33-1.47.2 php74-tokenizer-7.4.33-1.47.2 php74-tokenizer-debuginfo-7.4.33-1.47.2 php74-xmlreader-7.4.33-1.47.2 php74-xmlreader-debuginfo-7.4.33-1.47.2 php74-xmlrpc-7.4.33-1.47.2 php74-xmlrpc-debuginfo-7.4.33-1.47.2 php74-xmlwriter-7.4.33-1.47.2 php74-xmlwriter-debuginfo-7.4.33-1.47.2 php74-xsl-7.4.33-1.47.2 php74-xsl-debuginfo-7.4.33-1.47.2 php74-zip-7.4.33-1.47.2 php74-zip-debuginfo-7.4.33-1.47.2 php74-zlib-7.4.33-1.47.2 php74-zlib-debuginfo-7.4.33-1.47.2 References: https://www.suse.com/security/cve/CVE-2017-8923.html https://www.suse.com/security/cve/CVE-2020-7068.html https://www.suse.com/security/cve/CVE-2020-7069.html https://www.suse.com/security/cve/CVE-2020-7070.html https://www.suse.com/security/cve/CVE-2020-7071.html https://www.suse.com/security/cve/CVE-2021-21702.html https://www.suse.com/security/cve/CVE-2021-21703.html https://www.suse.com/security/cve/CVE-2021-21704.html https://www.suse.com/security/cve/CVE-2021-21705.html https://www.suse.com/security/cve/CVE-2021-21706.html https://www.suse.com/security/cve/CVE-2021-21707.html https://www.suse.com/security/cve/CVE-2021-21708.html https://www.suse.com/security/cve/CVE-2022-31625.html https://www.suse.com/security/cve/CVE-2022-31626.html https://www.suse.com/security/cve/CVE-2022-31628.html https://www.suse.com/security/cve/CVE-2022-31629.html https://www.suse.com/security/cve/CVE-2022-31630.html https://www.suse.com/security/cve/CVE-2022-37454.html https://bugzilla.suse.com/1203867 https://bugzilla.suse.com/1203870 https://bugzilla.suse.com/1204577 https://bugzilla.suse.com/1204979 . SUSE Security Update for php80 tackles severe vulnerabilities within the software, providing essential updates alongside a significant feature upgrade.. php74 Update,SUSE Security Patch,SUSE Linux Feature Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 18, 2022 Important SuSE
100

SUSE Linux Enterprise: 2022:2161-1 Important: Php74 Buffer Overflow

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for php74 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2161-1 Rating: important References: #1200628 #1200645 Cross-References: CVE-2022-31625 CVE-2022-31626 CVSS scores: CVE-2022-31625 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-31626 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for php74 fixes the following issues: - CVE-2022-31625: Fixed uninitialized pointers free in Postgres extension. (bsc#1200645) - CVE-2022-31626: Fixed buffer overflow via user-supplied password when using pdo_mysql extension with mysqlnd driver. (bsc#1200628). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-2161=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2022-2161=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php74-debuginfo-7.4.6-1.42.1 php74-debugsource-7.4.6-1.42.1 php74-devel-7.4.6-1.42.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php74-7.4.6-1.42.1 apache2-mod_php74-debuginfo-7.4.6-1.42.1 php74-7.4.6-1.42.1 php74-bcmath-7.4.6-1.42.1 php74-bcmath-debuginfo-7.4.6-1.42.1 php74-bz2-7.4.6-1.42.1 php74-bz2-debuginfo-7.4.6-1.42.1 php74-calendar-7.4.6-1.42.1 php74-calendar-debuginfo-7.4.6-1.42.1 php74-ctype-7.4.6-1.42.1 php74-ctype-debuginfo-7.4.6-1.42.1 php74-curl-7.4.6-1.42.1 php74-curl-debuginfo-7.4.6-1.42.1 php74-dba-7.4.6-1.42.1 php74-dba-debuginfo-7.4.6-1.42.1 php74-debuginfo-7.4.6-1.42.1 php74-debugsource-7.4.6-1.42.1 php74-dom-7.4.6-1.42.1 php74-dom-debuginfo-7.4.6-1.42.1 php74-enchant-7.4.6-1.42.1 php74-enchant-debuginfo-7.4.6-1.42.1 php74-exif-7.4.6-1.42.1 php74-exif-debuginfo-7.4.6-1.42.1 php74-fastcgi-7.4.6-1.42.1 php74-fastcgi-debuginfo-7.4.6-1.42.1 php74-fileinfo-7.4.6-1.42.1 php74-fileinfo-debuginfo-7.4.6-1.42.1 php74-fpm-7.4.6-1.42.1 php74-fpm-debuginfo-7.4.6-1.42.1 php74-ftp-7.4.6-1.42.1 php74-ftp-debuginfo-7.4.6-1.42.1 php74-gd-7.4.6-1.42.1 php74-gd-debuginfo-7.4.6-1.42.1 php74-gettext-7.4.6-1.42.1 php74-gettext-debuginfo-7.4.6-1.42.1 php74-gmp-7.4.6-1.42.1 php74-gmp-debuginfo-7.4.6-1.42.1 php74-iconv-7.4.6-1.42.1 php74-iconv-debuginfo-7.4.6-1.42.1 php74-intl-7.4.6-1.42.1 php74-intl-debuginfo-7.4.6-1.42.1 php74-json-7.4.6-1.42.1 php74-json-debuginfo-7.4.6-1.42.1 php74-ldap-7.4.6-1.42.1 php74-ldap-debuginfo-7.4.6-1.42.1 php74-mbstring-7.4.6-1.42.1 php74-mbstring-debuginfo-7.4.6-1.42.1 php74-mysql-7.4.6-1.42.1 php74-mysql-debuginfo-7.4.6-1.42.1 php74-odbc-7.4.6-1.42.1 php74-odbc-debuginfo-7.4.6-1.42.1 php74-opcache-7.4.6-1.42.1 php74-opcache-debuginfo-7.4.6-1.42.1 php74-openssl-7.4.6-1.42.1 php74-openssl-debuginfo-7.4.6-1.42.1 php74-pcntl-7.4.6-1.42.1 php74-pcntl-debuginfo-7.4.6-1.42.1 php74-pdo-7.4.6-1.42.1 php74-pdo-debuginfo-7.4.6-1.42.1 php74-pgsql-7.4.6-1.42.1 php74-pgsql-debuginfo-7.4.6-1.42.1 php74-phar-7.4.6-1.42.1 php74-phar-debuginfo-7.4.6-1.42.1 php74-posix-7.4.6-1.42.1 php74-posix-debuginfo-7.4.6-1.42.1 php74-readline-7.4.6-1.42.1 php74-readline-debuginfo-7.4.6-1.42.1 php74-shmop-7.4.6-1.42.1 php74-shmop-debuginfo-7.4.6-1.42.1 php74-snmp-7.4.6-1.42.1 php74-snmp-debuginfo-7.4.6-1.42.1 php74-soap-7.4.6-1.42.1 php74-soap-debuginfo-7.4.6-1.42.1 php74-sockets-7.4.6-1.42.1 php74-sockets-debuginfo-7.4.6-1.42.1 php74-sodium-7.4.6-1.42.1 php74-sodium-debuginfo-7.4.6-1.42.1 php74-sqlite-7.4.6-1.42.1 php74-sqlite-debuginfo-7.4.6-1.42.1 php74-sysvmsg-7.4.6-1.42.1 php74-sysvmsg-debuginfo-7.4.6-1.42.1 php74-sysvsem-7.4.6-1.42.1 php74-sysvsem-debuginfo-7.4.6-1.42.1 php74-sysvshm-7.4.6-1.42.1 php74-sysvshm-debuginfo-7.4.6-1.42.1 php74-tidy-7.4.6-1.42.1 php74-tidy-debuginfo-7.4.6-1.42.1 php74-tokenizer-7.4.6-1.42.1 php74-tokenizer-debuginfo-7.4.6-1.42.1 php74-xmlreader-7.4.6-1.42.1 php74-xmlreader-debuginfo-7.4.6-1.42.1 php74-xmlrpc-7.4.6-1.42.1 php74-xmlrpc-debuginfo-7.4.6-1.42.1 php74-xmlwriter-7.4.6-1.42.1 php74-xmlwriter-debuginfo-7.4.6-1.42.1 php74-xsl-7.4.6-1.42.1 php74-xsl-debuginfo-7.4.6-1.42.1 php74-zip-7.4.6-1.42.1 php74-zip-debuginfo-7.4.6-1.42.1 php74-zlib-7.4.6-1.42.1 php74-zlib-debuginfo-7.4.6-1.42.1 References: https://www.suse.com/security/cve/CVE-2022-31625.html https://www.suse.com/security/cve/CVE-2022-31626.html https://bugzilla.suse.com/1200628 https://bugzilla.suse.com/1200645 . SUSE Security Notification: Critical patch released for php74 addressing two vulnerabilities related to buffer overflow and improper pointer initialization.. SUSE Linux Enterprise, Php74 Security Update, Software Patches, Security Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 23, 2022 Important SuSE
100

SUSE: 2022:1893-1 Low Severity: Filter Bypass in php74 Security Issue

An update that contains security fixes can now be installed. . SUSE Security Update: Security update for php74 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1893-1 Rating: low References: #1197644 Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for php74 fixes the following issues: - Fixed filter_var bypass vulnerability (bsc#1197644). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-1893=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2022-1893=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php74-debuginfo-7.4.6-1.39.5 php74-debugsource-7.4.6-1.39.5 php74-devel-7.4.6-1.39.5 - SUSE Linux Enterprise Module for WebScripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php74-7.4.6-1.39.5 apache2-mod_php74-debuginfo-7.4.6-1.39.5 php74-7.4.6-1.39.5 php74-bcmath-7.4.6-1.39.5 php74-bcmath-debuginfo-7.4.6-1.39.5 php74-bz2-7.4.6-1.39.5 php74-bz2-debuginfo-7.4.6-1.39.5 php74-calendar-7.4.6-1.39.5 php74-calendar-debuginfo-7.4.6-1.39.5 php74-ctype-7.4.6-1.39.5 php74-ctype-debuginfo-7.4.6-1.39.5 php74-curl-7.4.6-1.39.5 php74-curl-debuginfo-7.4.6-1.39.5 php74-dba-7.4.6-1.39.5 php74-dba-debuginfo-7.4.6-1.39.5 php74-debuginfo-7.4.6-1.39.5 php74-debugsource-7.4.6-1.39.5 php74-dom-7.4.6-1.39.5 php74-dom-debuginfo-7.4.6-1.39.5 php74-enchant-7.4.6-1.39.5 php74-enchant-debuginfo-7.4.6-1.39.5 php74-exif-7.4.6-1.39.5 php74-exif-debuginfo-7.4.6-1.39.5 php74-fastcgi-7.4.6-1.39.5 php74-fastcgi-debuginfo-7.4.6-1.39.5 php74-fileinfo-7.4.6-1.39.5 php74-fileinfo-debuginfo-7.4.6-1.39.5 php74-fpm-7.4.6-1.39.5 php74-fpm-debuginfo-7.4.6-1.39.5 php74-ftp-7.4.6-1.39.5 php74-ftp-debuginfo-7.4.6-1.39.5 php74-gd-7.4.6-1.39.5 php74-gd-debuginfo-7.4.6-1.39.5 php74-gettext-7.4.6-1.39.5 php74-gettext-debuginfo-7.4.6-1.39.5 php74-gmp-7.4.6-1.39.5 php74-gmp-debuginfo-7.4.6-1.39.5 php74-iconv-7.4.6-1.39.5 php74-iconv-debuginfo-7.4.6-1.39.5 php74-intl-7.4.6-1.39.5 php74-intl-debuginfo-7.4.6-1.39.5 php74-json-7.4.6-1.39.5 php74-json-debuginfo-7.4.6-1.39.5 php74-ldap-7.4.6-1.39.5 php74-ldap-debuginfo-7.4.6-1.39.5 php74-mbstring-7.4.6-1.39.5 php74-mbstring-debuginfo-7.4.6-1.39.5 php74-mysql-7.4.6-1.39.5 php74-mysql-debuginfo-7.4.6-1.39.5 php74-odbc-7.4.6-1.39.5 php74-odbc-debuginfo-7.4.6-1.39.5 php74-opcache-7.4.6-1.39.5 php74-opcache-debuginfo-7.4.6-1.39.5 php74-openssl-7.4.6-1.39.5 php74-openssl-debuginfo-7.4.6-1.39.5 php74-pcntl-7.4.6-1.39.5 php74-pcntl-debuginfo-7.4.6-1.39.5 php74-pdo-7.4.6-1.39.5 php74-pdo-debuginfo-7.4.6-1.39.5 php74-pgsql-7.4.6-1.39.5 php74-pgsql-debuginfo-7.4.6-1.39.5 php74-phar-7.4.6-1.39.5 php74-phar-debuginfo-7.4.6-1.39.5 php74-posix-7.4.6-1.39.5 php74-posix-debuginfo-7.4.6-1.39.5 php74-readline-7.4.6-1.39.5 php74-readline-debuginfo-7.4.6-1.39.5 php74-shmop-7.4.6-1.39.5 php74-shmop-debuginfo-7.4.6-1.39.5 php74-snmp-7.4.6-1.39.5 php74-snmp-debuginfo-7.4.6-1.39.5 php74-soap-7.4.6-1.39.5 php74-soap-debuginfo-7.4.6-1.39.5 php74-sockets-7.4.6-1.39.5 php74-sockets-debuginfo-7.4.6-1.39.5 php74-sodium-7.4.6-1.39.5 php74-sodium-debuginfo-7.4.6-1.39.5 php74-sqlite-7.4.6-1.39.5 php74-sqlite-debuginfo-7.4.6-1.39.5 php74-sysvmsg-7.4.6-1.39.5 php74-sysvmsg-debuginfo-7.4.6-1.39.5 php74-sysvsem-7.4.6-1.39.5 php74-sysvsem-debuginfo-7.4.6-1.39.5 php74-sysvshm-7.4.6-1.39.5 php74-sysvshm-debuginfo-7.4.6-1.39.5 php74-tidy-7.4.6-1.39.5 php74-tidy-debuginfo-7.4.6-1.39.5 php74-tokenizer-7.4.6-1.39.5 php74-tokenizer-debuginfo-7.4.6-1.39.5 php74-xmlreader-7.4.6-1.39.5 php74-xmlreader-debuginfo-7.4.6-1.39.5 php74-xmlrpc-7.4.6-1.39.5 php74-xmlrpc-debuginfo-7.4.6-1.39.5 php74-xmlwriter-7.4.6-1.39.5 php74-xmlwriter-debuginfo-7.4.6-1.39.5 php74-xsl-7.4.6-1.39.5 php74-xsl-debuginfo-7.4.6-1.39.5 php74-zip-7.4.6-1.39.5 php74-zip-debuginfo-7.4.6-1.39.5 php74-zlib-7.4.6-1.39.5 php74-zlib-debuginfo-7.4.6-1.39.5 References: https://bugzilla.suse.com/1197644 . This enhancement resolves a vulnerability in php74 for SUSE, reinforcing security protocols for online platforms.. php74 Security Update,SUSE Linux,Low Severity Fixes,PHP Filter Bypass. . Severity: Low. LinuxSecurity.com Team

Calendar 2 May 31, 2022 Low SuSE
100

SUSE: 2022:0654-1 Important: php74 Use After Free Critical Threat

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php74 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0654-1 Rating: important References: #1196252 Cross-References: CVE-2021-21708 CVSS scores: CVE-2021-21708 (SUSE): 7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Web Scripting 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php74 fixes the following issues: - CVE-2021-21708: Fixed use after free due to php_filter_float() failing for ints (bsc#1196252). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-654=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2022-654=1 Package List: - SUSE Linux Enterprise Software Development Kit12-SP5 (aarch64 ppc64le s390x x86_64): php74-debuginfo-7.4.6-1.36.1 php74-debugsource-7.4.6-1.36.1 php74-devel-7.4.6-1.36.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php74-7.4.6-1.36.1 apache2-mod_php74-debuginfo-7.4.6-1.36.1 php74-7.4.6-1.36.1 php74-bcmath-7.4.6-1.36.1 php74-bcmath-debuginfo-7.4.6-1.36.1 php74-bz2-7.4.6-1.36.1 php74-bz2-debuginfo-7.4.6-1.36.1 php74-calendar-7.4.6-1.36.1 php74-calendar-debuginfo-7.4.6-1.36.1 php74-ctype-7.4.6-1.36.1 php74-ctype-debuginfo-7.4.6-1.36.1 php74-curl-7.4.6-1.36.1 php74-curl-debuginfo-7.4.6-1.36.1 php74-dba-7.4.6-1.36.1 php74-dba-debuginfo-7.4.6-1.36.1 php74-debuginfo-7.4.6-1.36.1 php74-debugsource-7.4.6-1.36.1 php74-dom-7.4.6-1.36.1 php74-dom-debuginfo-7.4.6-1.36.1 php74-enchant-7.4.6-1.36.1 php74-enchant-debuginfo-7.4.6-1.36.1 php74-exif-7.4.6-1.36.1 php74-exif-debuginfo-7.4.6-1.36.1 php74-fastcgi-7.4.6-1.36.1 php74-fastcgi-debuginfo-7.4.6-1.36.1 php74-fileinfo-7.4.6-1.36.1 php74-fileinfo-debuginfo-7.4.6-1.36.1 php74-fpm-7.4.6-1.36.1 php74-fpm-debuginfo-7.4.6-1.36.1 php74-ftp-7.4.6-1.36.1 php74-ftp-debuginfo-7.4.6-1.36.1 php74-gd-7.4.6-1.36.1 php74-gd-debuginfo-7.4.6-1.36.1 php74-gettext-7.4.6-1.36.1 php74-gettext-debuginfo-7.4.6-1.36.1 php74-gmp-7.4.6-1.36.1 php74-gmp-debuginfo-7.4.6-1.36.1 php74-iconv-7.4.6-1.36.1 php74-iconv-debuginfo-7.4.6-1.36.1 php74-intl-7.4.6-1.36.1 php74-intl-debuginfo-7.4.6-1.36.1 php74-json-7.4.6-1.36.1 php74-json-debuginfo-7.4.6-1.36.1 php74-ldap-7.4.6-1.36.1 php74-ldap-debuginfo-7.4.6-1.36.1 php74-mbstring-7.4.6-1.36.1 php74-mbstring-debuginfo-7.4.6-1.36.1 php74-mysql-7.4.6-1.36.1 php74-mysql-debuginfo-7.4.6-1.36.1 php74-odbc-7.4.6-1.36.1 php74-odbc-debuginfo-7.4.6-1.36.1 php74-opcache-7.4.6-1.36.1 php74-opcache-debuginfo-7.4.6-1.36.1 php74-openssl-7.4.6-1.36.1 php74-openssl-debuginfo-7.4.6-1.36.1 php74-pcntl-7.4.6-1.36.1 php74-pcntl-debuginfo-7.4.6-1.36.1 php74-pdo-7.4.6-1.36.1 php74-pdo-debuginfo-7.4.6-1.36.1 php74-pgsql-7.4.6-1.36.1 php74-pgsql-debuginfo-7.4.6-1.36.1 php74-phar-7.4.6-1.36.1 php74-phar-debuginfo-7.4.6-1.36.1 php74-posix-7.4.6-1.36.1 php74-posix-debuginfo-7.4.6-1.36.1 php74-readline-7.4.6-1.36.1 php74-readline-debuginfo-7.4.6-1.36.1 php74-shmop-7.4.6-1.36.1 php74-shmop-debuginfo-7.4.6-1.36.1 php74-snmp-7.4.6-1.36.1 php74-snmp-debuginfo-7.4.6-1.36.1 php74-soap-7.4.6-1.36.1 php74-soap-debuginfo-7.4.6-1.36.1 php74-sockets-7.4.6-1.36.1 php74-sockets-debuginfo-7.4.6-1.36.1 php74-sodium-7.4.6-1.36.1 php74-sodium-debuginfo-7.4.6-1.36.1 php74-sqlite-7.4.6-1.36.1 php74-sqlite-debuginfo-7.4.6-1.36.1 php74-sysvmsg-7.4.6-1.36.1 php74-sysvmsg-debuginfo-7.4.6-1.36.1 php74-sysvsem-7.4.6-1.36.1 php74-sysvsem-debuginfo-7.4.6-1.36.1 php74-sysvshm-7.4.6-1.36.1 php74-sysvshm-debuginfo-7.4.6-1.36.1 php74-tidy-7.4.6-1.36.1 php74-tidy-debuginfo-7.4.6-1.36.1 php74-tokenizer-7.4.6-1.36.1 php74-tokenizer-debuginfo-7.4.6-1.36.1 php74-xmlreader-7.4.6-1.36.1 php74-xmlreader-debuginfo-7.4.6-1.36.1 php74-xmlrpc-7.4.6-1.36.1 php74-xmlrpc-debuginfo-7.4.6-1.36.1 php74-xmlwriter-7.4.6-1.36.1 php74-xmlwriter-debuginfo-7.4.6-1.36.1 php74-xsl-7.4.6-1.36.1 php74-xsl-debuginfo-7.4.6-1.36.1 php74-zip-7.4.6-1.36.1 php74-zip-debuginfo-7.4.6-1.36.1 php74-zlib-7.4.6-1.36.1 php74-zlib-debuginfo-7.4.6-1.36.1 References: https://www.suse.com/security/cve/CVE-2021-21708.html https://bugzilla.suse.com/1196252 . Update php74 to address a serious use-after-free flawdisclosed in SUSE Security Update: SUSE-SU-2022:0654-1.. php74 Fixes, SUSE Updates, Security Advisory, Linux Software, Use After Free. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 01, 2022 Important SuSE
100

SUSE: 2021:0522-1 Important Update for php74 NULL Pointer Dereference

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php74 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0522-1 Rating: important References: #1182049 Cross-References: CVE-2021-21702 CVSS scores: CVE-2021-21702 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php74 fixes the following issues: - CVE-2021-21702 [bsc#1182049]: NULL pointer dereference in SoapClient Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-522=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-522=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php74-debuginfo-7.4.6-1.19.1 php74-debugsource-7.4.6-1.19.1 php74-devel-7.4.6-1.19.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php74-7.4.6-1.19.1 apache2-mod_php74-debuginfo-7.4.6-1.19.1 php74-7.4.6-1.19.1 php74-bcmath-7.4.6-1.19.1 php74-bcmath-debuginfo-7.4.6-1.19.1 php74-bz2-7.4.6-1.19.1 php74-bz2-debuginfo-7.4.6-1.19.1 php74-calendar-7.4.6-1.19.1 php74-calendar-debuginfo-7.4.6-1.19.1 php74-ctype-7.4.6-1.19.1 php74-ctype-debuginfo-7.4.6-1.19.1 php74-curl-7.4.6-1.19.1 php74-curl-debuginfo-7.4.6-1.19.1 php74-dba-7.4.6-1.19.1 php74-dba-debuginfo-7.4.6-1.19.1 php74-debuginfo-7.4.6-1.19.1 php74-debugsource-7.4.6-1.19.1 php74-dom-7.4.6-1.19.1 php74-dom-debuginfo-7.4.6-1.19.1 php74-enchant-7.4.6-1.19.1 php74-enchant-debuginfo-7.4.6-1.19.1 php74-exif-7.4.6-1.19.1 php74-exif-debuginfo-7.4.6-1.19.1 php74-fastcgi-7.4.6-1.19.1 php74-fastcgi-debuginfo-7.4.6-1.19.1 php74-fileinfo-7.4.6-1.19.1 php74-fileinfo-debuginfo-7.4.6-1.19.1 php74-fpm-7.4.6-1.19.1 php74-fpm-debuginfo-7.4.6-1.19.1 php74-ftp-7.4.6-1.19.1 php74-ftp-debuginfo-7.4.6-1.19.1 php74-gd-7.4.6-1.19.1 php74-gd-debuginfo-7.4.6-1.19.1 php74-gettext-7.4.6-1.19.1 php74-gettext-debuginfo-7.4.6-1.19.1 php74-gmp-7.4.6-1.19.1 php74-gmp-debuginfo-7.4.6-1.19.1 php74-iconv-7.4.6-1.19.1 php74-iconv-debuginfo-7.4.6-1.19.1 php74-intl-7.4.6-1.19.1 php74-intl-debuginfo-7.4.6-1.19.1 php74-json-7.4.6-1.19.1 php74-json-debuginfo-7.4.6-1.19.1 php74-ldap-7.4.6-1.19.1 php74-ldap-debuginfo-7.4.6-1.19.1 php74-mbstring-7.4.6-1.19.1 php74-mbstring-debuginfo-7.4.6-1.19.1 php74-mysql-7.4.6-1.19.1 php74-mysql-debuginfo-7.4.6-1.19.1 php74-odbc-7.4.6-1.19.1 php74-odbc-debuginfo-7.4.6-1.19.1 php74-opcache-7.4.6-1.19.1 php74-opcache-debuginfo-7.4.6-1.19.1 php74-openssl-7.4.6-1.19.1 php74-openssl-debuginfo-7.4.6-1.19.1 php74-pcntl-7.4.6-1.19.1 php74-pcntl-debuginfo-7.4.6-1.19.1 php74-pdo-7.4.6-1.19.1 php74-pdo-debuginfo-7.4.6-1.19.1 php74-pgsql-7.4.6-1.19.1 php74-pgsql-debuginfo-7.4.6-1.19.1 php74-phar-7.4.6-1.19.1 php74-phar-debuginfo-7.4.6-1.19.1 php74-posix-7.4.6-1.19.1 php74-posix-debuginfo-7.4.6-1.19.1 php74-readline-7.4.6-1.19.1 php74-readline-debuginfo-7.4.6-1.19.1 php74-shmop-7.4.6-1.19.1 php74-shmop-debuginfo-7.4.6-1.19.1 php74-snmp-7.4.6-1.19.1 php74-snmp-debuginfo-7.4.6-1.19.1 php74-soap-7.4.6-1.19.1 php74-soap-debuginfo-7.4.6-1.19.1 php74-sockets-7.4.6-1.19.1 php74-sockets-debuginfo-7.4.6-1.19.1 php74-sodium-7.4.6-1.19.1 php74-sodium-debuginfo-7.4.6-1.19.1 php74-sqlite-7.4.6-1.19.1 php74-sqlite-debuginfo-7.4.6-1.19.1 php74-sysvmsg-7.4.6-1.19.1 php74-sysvmsg-debuginfo-7.4.6-1.19.1 php74-sysvsem-7.4.6-1.19.1 php74-sysvsem-debuginfo-7.4.6-1.19.1 php74-sysvshm-7.4.6-1.19.1 php74-sysvshm-debuginfo-7.4.6-1.19.1 php74-tidy-7.4.6-1.19.1 php74-tidy-debuginfo-7.4.6-1.19.1 php74-tokenizer-7.4.6-1.19.1 php74-tokenizer-debuginfo-7.4.6-1.19.1 php74-xmlreader-7.4.6-1.19.1 php74-xmlreader-debuginfo-7.4.6-1.19.1 php74-xmlrpc-7.4.6-1.19.1 php74-xmlrpc-debuginfo-7.4.6-1.19.1 php74-xmlwriter-7.4.6-1.19.1 php74-xmlwriter-debuginfo-7.4.6-1.19.1 php74-xsl-7.4.6-1.19.1 php74-xsl-debuginfo-7.4.6-1.19.1 php74-zip-7.4.6-1.19.1 php74-zip-debuginfo-7.4.6-1.19.1 php74-zlib-7.4.6-1.19.1 php74-zlib-debuginfo-7.4.6-1.19.1 References: https://www.suse.com/security/cve/CVE-2021-21702.html https://bugzilla.suse.com/1182049 . SUSE Security Patch for php74 resolves a crucial NULL pointer dereference issue. Apply the update promptly to secure your system.. SUSE Linux, php74 Security Fix, Software Development Kit Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 19, 2021 Important SuSE
100

SUSE: 2021:0126-1 Moderate: php74 URL Filtering Vulnerability Advisory

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php74 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0126-1 Rating: moderate References: #1180706 Cross-References: CVE-2020-7071 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php74 fixes the following issue: - CVE-2020-7071: Fixed an insufficient filter in parse_url() that accepted URLs with invalid userinfo (bsc#1180706). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-126=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-126=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php74-debuginfo-7.4.6-1.16.1 php74-debugsource-7.4.6-1.16.1 php74-devel-7.4.6-1.16.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php74-7.4.6-1.16.1 apache2-mod_php74-debuginfo-7.4.6-1.16.1 php74-7.4.6-1.16.1 php74-bcmath-7.4.6-1.16.1 php74-bcmath-debuginfo-7.4.6-1.16.1 php74-bz2-7.4.6-1.16.1 php74-bz2-debuginfo-7.4.6-1.16.1 php74-calendar-7.4.6-1.16.1 php74-calendar-debuginfo-7.4.6-1.16.1 php74-ctype-7.4.6-1.16.1 php74-ctype-debuginfo-7.4.6-1.16.1 php74-curl-7.4.6-1.16.1 php74-curl-debuginfo-7.4.6-1.16.1 php74-dba-7.4.6-1.16.1 php74-dba-debuginfo-7.4.6-1.16.1 php74-debuginfo-7.4.6-1.16.1 php74-debugsource-7.4.6-1.16.1 php74-dom-7.4.6-1.16.1 php74-dom-debuginfo-7.4.6-1.16.1 php74-enchant-7.4.6-1.16.1 php74-enchant-debuginfo-7.4.6-1.16.1 php74-exif-7.4.6-1.16.1 php74-exif-debuginfo-7.4.6-1.16.1 php74-fastcgi-7.4.6-1.16.1 php74-fastcgi-debuginfo-7.4.6-1.16.1 php74-fileinfo-7.4.6-1.16.1 php74-fileinfo-debuginfo-7.4.6-1.16.1 php74-fpm-7.4.6-1.16.1 php74-fpm-debuginfo-7.4.6-1.16.1 php74-ftp-7.4.6-1.16.1 php74-ftp-debuginfo-7.4.6-1.16.1 php74-gd-7.4.6-1.16.1 php74-gd-debuginfo-7.4.6-1.16.1 php74-gettext-7.4.6-1.16.1 php74-gettext-debuginfo-7.4.6-1.16.1 php74-gmp-7.4.6-1.16.1 php74-gmp-debuginfo-7.4.6-1.16.1 php74-iconv-7.4.6-1.16.1 php74-iconv-debuginfo-7.4.6-1.16.1 php74-intl-7.4.6-1.16.1 php74-intl-debuginfo-7.4.6-1.16.1 php74-json-7.4.6-1.16.1 php74-json-debuginfo-7.4.6-1.16.1 php74-ldap-7.4.6-1.16.1 php74-ldap-debuginfo-7.4.6-1.16.1 php74-mbstring-7.4.6-1.16.1 php74-mbstring-debuginfo-7.4.6-1.16.1 php74-mysql-7.4.6-1.16.1 php74-mysql-debuginfo-7.4.6-1.16.1 php74-odbc-7.4.6-1.16.1 php74-odbc-debuginfo-7.4.6-1.16.1 php74-opcache-7.4.6-1.16.1 php74-opcache-debuginfo-7.4.6-1.16.1 php74-openssl-7.4.6-1.16.1 php74-openssl-debuginfo-7.4.6-1.16.1 php74-pcntl-7.4.6-1.16.1 php74-pcntl-debuginfo-7.4.6-1.16.1 php74-pdo-7.4.6-1.16.1 php74-pdo-debuginfo-7.4.6-1.16.1 php74-pgsql-7.4.6-1.16.1 php74-pgsql-debuginfo-7.4.6-1.16.1 php74-phar-7.4.6-1.16.1 php74-phar-debuginfo-7.4.6-1.16.1 php74-posix-7.4.6-1.16.1 php74-posix-debuginfo-7.4.6-1.16.1 php74-readline-7.4.6-1.16.1 php74-readline-debuginfo-7.4.6-1.16.1 php74-shmop-7.4.6-1.16.1 php74-shmop-debuginfo-7.4.6-1.16.1 php74-snmp-7.4.6-1.16.1 php74-snmp-debuginfo-7.4.6-1.16.1 php74-soap-7.4.6-1.16.1 php74-soap-debuginfo-7.4.6-1.16.1 php74-sockets-7.4.6-1.16.1 php74-sockets-debuginfo-7.4.6-1.16.1 php74-sodium-7.4.6-1.16.1 php74-sodium-debuginfo-7.4.6-1.16.1 php74-sqlite-7.4.6-1.16.1 php74-sqlite-debuginfo-7.4.6-1.16.1 php74-sysvmsg-7.4.6-1.16.1 php74-sysvmsg-debuginfo-7.4.6-1.16.1 php74-sysvsem-7.4.6-1.16.1 php74-sysvsem-debuginfo-7.4.6-1.16.1 php74-sysvshm-7.4.6-1.16.1 php74-sysvshm-debuginfo-7.4.6-1.16.1 php74-tidy-7.4.6-1.16.1 php74-tidy-debuginfo-7.4.6-1.16.1 php74-tokenizer-7.4.6-1.16.1 php74-tokenizer-debuginfo-7.4.6-1.16.1 php74-xmlreader-7.4.6-1.16.1 php74-xmlreader-debuginfo-7.4.6-1.16.1 php74-xmlrpc-7.4.6-1.16.1 php74-xmlrpc-debuginfo-7.4.6-1.16.1 php74-xmlwriter-7.4.6-1.16.1 php74-xmlwriter-debuginfo-7.4.6-1.16.1 php74-xsl-7.4.6-1.16.1 php74-xsl-debuginfo-7.4.6-1.16.1 php74-zip-7.4.6-1.16.1 php74-zip-debuginfo-7.4.6-1.16.1 php74-zlib-7.4.6-1.16.1 php74-zlib-debuginfo-7.4.6-1.16.1 References: https://www.suse.com/security/cve/CVE-2020-7071.html https://bugzilla.suse.com/1180706 . SUSE Security Patch addresses a significant concern in php74 concerning URL validation. It's advisable to apply the most recent update to improve overall security.. SUSE Linux, Php74 Update, Security Fixes. . LinuxSecurity.com Team

Calendar 2 Jan 14, 2021 SuSE
100

SUSE: 2020:2896-1 Important: php74 Remote Code Execution Issues

An update that solves two vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for php74 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2896-1 Rating: important References: #1173786 #1177351 #1177352 Cross-References: CVE-2020-7069 CVE-2020-7070 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for php74 fixes the following issues: - CVE-2020-7069: Fixed an issue when AES-CCM mode was used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV was used (bsc#1177351). - CVE-2020-7070: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1177352). - Added tmpfiles.d for php-fpm to provide a base for a socket (bsc#1173786) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-2896=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-2896=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php74-debuginfo-7.4.6-1.13.1 php74-debugsource-7.4.6-1.13.1 php74-devel-7.4.6-1.13.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php74-7.4.6-1.13.1 apache2-mod_php74-debuginfo-7.4.6-1.13.1 php74-7.4.6-1.13.1 php74-bcmath-7.4.6-1.13.1 php74-bcmath-debuginfo-7.4.6-1.13.1 php74-bz2-7.4.6-1.13.1 php74-bz2-debuginfo-7.4.6-1.13.1 php74-calendar-7.4.6-1.13.1 php74-calendar-debuginfo-7.4.6-1.13.1 php74-ctype-7.4.6-1.13.1 php74-ctype-debuginfo-7.4.6-1.13.1 php74-curl-7.4.6-1.13.1 php74-curl-debuginfo-7.4.6-1.13.1 php74-dba-7.4.6-1.13.1 php74-dba-debuginfo-7.4.6-1.13.1 php74-debuginfo-7.4.6-1.13.1 php74-debugsource-7.4.6-1.13.1 php74-dom-7.4.6-1.13.1 php74-dom-debuginfo-7.4.6-1.13.1 php74-enchant-7.4.6-1.13.1 php74-enchant-debuginfo-7.4.6-1.13.1 php74-exif-7.4.6-1.13.1 php74-exif-debuginfo-7.4.6-1.13.1 php74-fastcgi-7.4.6-1.13.1 php74-fastcgi-debuginfo-7.4.6-1.13.1 php74-fileinfo-7.4.6-1.13.1 php74-fileinfo-debuginfo-7.4.6-1.13.1 php74-fpm-7.4.6-1.13.1 php74-fpm-debuginfo-7.4.6-1.13.1 php74-ftp-7.4.6-1.13.1 php74-ftp-debuginfo-7.4.6-1.13.1 php74-gd-7.4.6-1.13.1 php74-gd-debuginfo-7.4.6-1.13.1 php74-gettext-7.4.6-1.13.1 php74-gettext-debuginfo-7.4.6-1.13.1 php74-gmp-7.4.6-1.13.1 php74-gmp-debuginfo-7.4.6-1.13.1 php74-iconv-7.4.6-1.13.1 php74-iconv-debuginfo-7.4.6-1.13.1 php74-intl-7.4.6-1.13.1 php74-intl-debuginfo-7.4.6-1.13.1 php74-json-7.4.6-1.13.1 php74-json-debuginfo-7.4.6-1.13.1 php74-ldap-7.4.6-1.13.1 php74-ldap-debuginfo-7.4.6-1.13.1 php74-mbstring-7.4.6-1.13.1 php74-mbstring-debuginfo-7.4.6-1.13.1 php74-mysql-7.4.6-1.13.1 php74-mysql-debuginfo-7.4.6-1.13.1 php74-odbc-7.4.6-1.13.1 php74-odbc-debuginfo-7.4.6-1.13.1 php74-opcache-7.4.6-1.13.1 php74-opcache-debuginfo-7.4.6-1.13.1 php74-openssl-7.4.6-1.13.1 php74-openssl-debuginfo-7.4.6-1.13.1 php74-pcntl-7.4.6-1.13.1 php74-pcntl-debuginfo-7.4.6-1.13.1 php74-pdo-7.4.6-1.13.1 php74-pdo-debuginfo-7.4.6-1.13.1 php74-pgsql-7.4.6-1.13.1 php74-pgsql-debuginfo-7.4.6-1.13.1 php74-phar-7.4.6-1.13.1 php74-phar-debuginfo-7.4.6-1.13.1 php74-posix-7.4.6-1.13.1 php74-posix-debuginfo-7.4.6-1.13.1 php74-readline-7.4.6-1.13.1 php74-readline-debuginfo-7.4.6-1.13.1 php74-shmop-7.4.6-1.13.1 php74-shmop-debuginfo-7.4.6-1.13.1 php74-snmp-7.4.6-1.13.1 php74-snmp-debuginfo-7.4.6-1.13.1 php74-soap-7.4.6-1.13.1 php74-soap-debuginfo-7.4.6-1.13.1 php74-sockets-7.4.6-1.13.1 php74-sockets-debuginfo-7.4.6-1.13.1 php74-sodium-7.4.6-1.13.1 php74-sodium-debuginfo-7.4.6-1.13.1 php74-sqlite-7.4.6-1.13.1 php74-sqlite-debuginfo-7.4.6-1.13.1 php74-sysvmsg-7.4.6-1.13.1 php74-sysvmsg-debuginfo-7.4.6-1.13.1 php74-sysvsem-7.4.6-1.13.1 php74-sysvsem-debuginfo-7.4.6-1.13.1 php74-sysvshm-7.4.6-1.13.1 php74-sysvshm-debuginfo-7.4.6-1.13.1 php74-tidy-7.4.6-1.13.1 php74-tidy-debuginfo-7.4.6-1.13.1 php74-tokenizer-7.4.6-1.13.1 php74-tokenizer-debuginfo-7.4.6-1.13.1 php74-xmlreader-7.4.6-1.13.1 php74-xmlreader-debuginfo-7.4.6-1.13.1 php74-xmlrpc-7.4.6-1.13.1 php74-xmlrpc-debuginfo-7.4.6-1.13.1 php74-xmlwriter-7.4.6-1.13.1 php74-xmlwriter-debuginfo-7.4.6-1.13.1 php74-xsl-7.4.6-1.13.1 php74-xsl-debuginfo-7.4.6-1.13.1 php74-zip-7.4.6-1.13.1 php74-zip-debuginfo-7.4.6-1.13.1 php74-zlib-7.4.6-1.13.1 php74-zlib-debuginfo-7.4.6-1.13.1 References: https://www.suse.com/security/cve/CVE-2020-7069.html https://www.suse.com/security/cve/CVE-2020-7070.html https://bugzilla.suse.com/1173786 https://bugzilla.suse.com/1177351 https://bugzilla.suse.com/1177352 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . This important SUSE Security Patch addresses multiple flaws within php74,strengthening your system's protection from potential risks.. SUSE Security Update, php74 vulnerabilities, remote code execution, security fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 13, 2020 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here