FlawAtlas
Search the atlas
SUSE-SU-2023:0527-1 Not scored

Security update for php8

This update for php8 fixes the following issues: php8 was updated to version 8.0.28: - CVE-2023-0568: Fixed NULL byte off-by-one in php_check_specific_open_basedir (bnc#1208366). - CVE-2023-0662: Fixed DoS vulnerability when parsing multipart request body (bnc#1208367).

Exploit probability Not scored
Published February 27, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Web and Scripting 15 SP4 apache2-mod_php8
SUSE:Linux Enterprise Module for Web and Scripting 15 SP4 php8
SUSE:Linux Enterprise Module for Web and Scripting 15 SP4 php8-embed
SUSE:Linux Enterprise Module for Web and Scripting 15 SP4 php8-fastcgi
SUSE:Linux Enterprise Module for Web and Scripting 15 SP4 php8-fpm
SUSE:Linux Enterprise Module for Web and Scripting 15 SP4 php8-test
openSUSE:Leap 15.4 apache2-mod_php8
openSUSE:Leap 15.4 php8
openSUSE:Leap 15.4 php8-embed
openSUSE:Leap 15.4 php8-fastcgi
openSUSE:Leap 15.4 php8-fpm
openSUSE:Leap 15.4 php8-test

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:0527-1

This update for php8 fixes the following issues: php8 was updated to version 8.0.28: - CVE-2023-0568: Fixed NULL byte off-by-one in php_check_specific_open_basedir (bnc#1208366). - CVE-2023-0662: Fixed DoS vulnerability when parsing multipart request body (bnc#1208367).

View original source

05 / REFERENCES

Further evidence