Security update for php7
This update for php7 fixes the following issues: - CVE-2021-21707: Fixed a special character breaks path in xml parsing. (bsc#1193041) - CVE-2022-31625: Fixed uninitialized pointers free in Postgres extension. (bsc#1200645) - CVE-2022-31626: Fixed buffer overflow via user-supplied password when using pdo_mysql extension with mysqlnd driver. (bsc#1200628)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for php7 fixes the following issues: - CVE-2021-21707: Fixed a special character breaks path in xml parsing. (bsc#1193041) - CVE-2022-31625: Fixed uninitialized pointers free in Postgres extension. (bsc#1200645) - CVE-2022-31626: Fixed buffer overflow via user-supplied password when using pdo_mysql extension with mysqlnd driver. (bsc#1200628)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1193041
- https://bugzilla.suse.com/1200628
- https://bugzilla.suse.com/1200645
- https://www.suse.com/security/cve/CVE-2021-21707
- https://www.suse.com/security/cve/CVE-2022-31625
- https://www.suse.com/security/cve/CVE-2022-31626
- https://www.suse.com/support/update/announcement/2022/suse-su-20222292-1/