Security update for php7
This update for php7 fixes the following issues: - Version update to 7.4.33: - CVE-2022-31630: Fixed out-of-bounds read due to insufficient input validation in imageloadfont() (bsc#1204979). - CVE-2022-37454: Fixed buffer overflow in hash_update() on long parameter (bsc#1204577). - Version update to 7.4.32 (jsc#SLE-23639) - CVE-2022-31628: Fixed an uncontrolled recursion in the phar uncompressor while decompressing 'quines' gzip files. (bsc#1203867) - CVE-2022-31629: Fixed a bug which could lead an attacker to set an insecure cookie that will treated as secure in the victim's browser. (bsc#1203870)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for php7 fixes the following issues: - Version update to 7.4.33: - CVE-2022-31630: Fixed out-of-bounds read due to insufficient input validation in imageloadfont() (bsc#1204979). - CVE-2022-37454: Fixed buffer overflow in hash_update() on long parameter (bsc#1204577). - Version update to 7.4.32 (jsc#SLE-23639) - CVE-2022-31628: Fixed an uncontrolled recursion in the phar uncompressor while decompressing 'quines' gzip files. (bsc#1203867) - CVE-2022-31629: Fixed a bug which could lead an attacker to set an insecure cookie that will treated as secure in the victim's browser. (bsc#1203870)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1203867
- https://bugzilla.suse.com/1203870
- https://bugzilla.suse.com/1204577
- https://bugzilla.suse.com/1204979
- https://www.suse.com/security/cve/CVE-2021-21707
- https://www.suse.com/security/cve/CVE-2021-21708
- https://www.suse.com/security/cve/CVE-2022-31625
- https://www.suse.com/security/cve/CVE-2022-31626
- https://www.suse.com/security/cve/CVE-2022-31628
- https://www.suse.com/security/cve/CVE-2022-31629
- https://www.suse.com/security/cve/CVE-2022-31630
- https://www.suse.com/security/cve/CVE-2022-37454
- https://www.suse.com/support/update/announcement/2022/suse-su-20223997-1/