SUSE-SU-2022:4068-1
Dashboard / Vulnerabilities / SUSE-SU-2022:4068-1
SUSE-SU-2022:4068-1
Summary: Security update for php74
Details: This update for php74 fixes the following issues: - Version update to 7.4.33: - CVE-2022-31630: Fixed out-of-bounds read due to insufficient input validation in imageloadfont() (bsc#1204979). - CVE-2022-37454: Fixed buffer overflow in hash_update() on long parameter (bsc#1204577). - Version update to 7.4.32 (jsc#SLE-23639) - CVE-2022-31628: Fixed an uncontrolled recursion in the phar uncompressor while decompressing 'quines' gzip files. (bsc#1203867) - CVE-2022-31629: Fixed a bug which could lead an attacker to set an insecure cookie that will treated as secure in the victim's browser. (bsc#1203870)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/, https://bugzilla.suse.com/1203867, https://bugzilla.suse.com/1203870, https://bugzilla.suse.com/1204577, https://bugzilla.suse.com/1204979, https://www.suse.com/security/cve/CVE-2017-8923, https://www.suse.com/security/cve/CVE-2020-7068, https://www.suse.com/security/cve/CVE-2020-7069, https://www.suse.com/security/cve/CVE-2020-7070, https://www.suse.com/security/cve/CVE-2020-7071, https://www.suse.com/security/cve/CVE-2021-21702, https://www.suse.com/security/cve/CVE-2021-21703, https://www.suse.com/security/cve/CVE-2021-21704, https://www.suse.com/security/cve/CVE-2021-21705, https://www.suse.com/security/cve/CVE-2021-21706, https://www.suse.com/security/cve/CVE-2021-21707, https://www.suse.com/security/cve/CVE-2021-21708, https://www.suse.com/security/cve/CVE-2022-31625, https://www.suse.com/security/cve/CVE-2022-31626, https://www.suse.com/security/cve/CVE-2022-31628, https://www.suse.com/security/cve/CVE-2022-31629, https://www.suse.com/security/cve/CVE-2022-31630, https://www.suse.com/security/cve/CVE-2022-37454
Affected packages
Package
Name: php74
Purl: pkg:rpm/suse/php74&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012
Affected ranges
Type: ECOSYSTEM
Events:
