CLSA-2021-1639681846
Dashboard / Vulnerabilities / CLSA-2021-1639681846
CLSA-2021-1639681846
Summary: Fix CVE(s): CVE-2020-7071, CVE-2020-7068, CVE-2021-21705, CVE-2021-21704, CVE-2021-21703, CVE-2021-21702
Details: * SECURITY UPDATE: Process crash and information disclosure - debian/patches/CVE-2020-7068.patch: fix access-after-free for actual_alias pointer - CVE-2020-7068 * SECURITY UPDATE: logic error due to invalid input validation - debian/patches/CVE-2020-7071.patch: add validation fo url->user field - CVE-2020-7071 * SECURITY UPDATE: program crash due to null pointer dereference - debian/patches/CVE-2021-21702.patch: pass empty string instead for NULL pointers to soap_error1(). Check NULL pointer in attr_is_equal_ex() and node_is_equal_ex() - CVE-2021-21702 * SECURITY UPDATE: integer overflow and subsequent incorrect buffer allocation - debian/patches/CVE-2021-21704.patch: add checks that prevent the overflow, replace strcat() with more secure strlcat() - CVE-2021-21704 * SECURITY UPDATE: logic error due to incorrect input validation - debian/patches/CVE-2021-21705.patch: fix validation of url password with FILTER_VALIDATE_URL parameter, - CVE-2021-21705 * SECURITY UPDATE: priv escalation due to shared memory between worker processes - debian/patches/CVE-2021-21703.patch: change scoreboard->proc type to array of structs and use scoreboard->nprocs only in child processes - CVE-2021-21703
Affected packages
Package
Name: libapache2-mod-php7.0
Purl: pkg:deb/tuxcare/libapache2-mod-php7.0?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
