OESA-2023-1566
Dashboard / Vulnerabilities / OESA-2023-1566
Summary: php security update
Details: PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. Security Fix(es): In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.(CVE-2022-31628)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1566, https://nvd.nist.gov/vuln/detail/CVE-2022-31628
Affected packages
Package
Name: php
Purl: pkg:rpm/openEuler/php&distro=openEuler-22.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
