USN-6305-2
Dashboard / Vulnerabilities / USN-6305-2
USN-6305-2
Summary: php7.0, php7.2, php7.4 vulnerabilities
Details: USN-6305-1 fixed several vulnerabilities in PHP. This update provides the corresponding update for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that PHP incorrectly handled certain XML files. An attacker could possibly use this issue to expose sensitive information. (CVE-2023-3823) It was discovered that PHP incorrectly handled certain PHAR files. An attacker could possibly use this issue to cause a crash, expose sensitive information or execute arbitrary code. (CVE-2023-3824)
References: https://ubuntu.com/security/notices/USN-6305-2, https://ubuntu.com/security/CVE-2023-3823, https://ubuntu.com/security/CVE-2023-3824, https://launchpad.net/bugs/2054511
Affected packages
Package
Name: php7.0
Purl: pkg:deb/ubuntu/php7.0?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
