Security update for php7
This update for php7 fixes the following issues: - CVE-2023-0568: Fixed NULL byte off-by-one in php_check_specific_open_basedir (bnc#1208366). - CVE-2023-0662: Fixed DoS vulnerability when parsing multipart request body (bnc#1208367). - CVE-2023-0567: Fixed vulnerability where BCrypt hashes erroneously validate if the salt is cut short by `$` (bsc#1208388).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for php7 fixes the following issues: - CVE-2023-0568: Fixed NULL byte off-by-one in php_check_specific_open_basedir (bnc#1208366). - CVE-2023-0662: Fixed DoS vulnerability when parsing multipart request body (bnc#1208367). - CVE-2023-0567: Fixed vulnerability where BCrypt hashes erroneously validate if the salt is cut short by `$` (bsc#1208388).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1208366
- https://bugzilla.suse.com/1208367
- https://bugzilla.suse.com/1208388
- https://www.suse.com/security/cve/CVE-2023-0567
- https://www.suse.com/security/cve/CVE-2023-0568
- https://www.suse.com/security/cve/CVE-2023-0662
- https://www.suse.com/support/update/announcement/2023/suse-su-20230514-1/