Security update for php8
This update for php8 fixes the following issues: - php8 was updated to version 8.0.24 - php8 was updated to version 8.0.23 (jsc#SLE-23639). - CVE-2021-21703: Fixed a local privilege escalation via PHP-FPM. (bsc#1192050) - CVE-2022-31628: Fixed an uncontrolled recursion in the phar uncompressor while decompressing 'quines' gzip files. (bsc#1203867) - CVE-2022-31629: Fixed a bug which could lead an attacker to set an insecure cookie that will treated as secure in the victim's browser. (bsc#1203870) - Fixed missing devel package requires pear and pecl extensions (jsc#SLE-24723, bsc#1200772).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for php8 fixes the following issues: - php8 was updated to version 8.0.24 - php8 was updated to version 8.0.23 (jsc#SLE-23639). - CVE-2021-21703: Fixed a local privilege escalation via PHP-FPM. (bsc#1192050) - CVE-2022-31628: Fixed an uncontrolled recursion in the phar uncompressor while decompressing 'quines' gzip files. (bsc#1203867) - CVE-2022-31629: Fixed a bug which could lead an attacker to set an insecure cookie that will treated as secure in the victim's browser. (bsc#1203870) - Fixed missing devel package requires pear and pecl extensions (jsc#SLE-24723, bsc#1200772).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1192050
- https://bugzilla.suse.com/1200772
- https://bugzilla.suse.com/1203867
- https://bugzilla.suse.com/1203870
- https://www.suse.com/security/cve/CVE-2021-21703
- https://www.suse.com/security/cve/CVE-2022-31628
- https://www.suse.com/security/cve/CVE-2022-31629
- https://www.suse.com/support/update/announcement/2022/suse-su-20223661-1/