Security update for php7
This update for php7 fixes the following issues: - CVE-2024-2756: Fixed bypass of security fix applied for CVE-2022-31629 that lead PHP to consider not secure cookies as secure (bsc#1222857) - CVE-2024-3096: Fixed bypass on null byte leading passwords checked via password_verify (bsc#1222858) - CVE-2024-5458: Fixed an issue that allows to bypass filters in filter_var FILTER_VALIDATE_URL. (bsc#1226073)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for php7 fixes the following issues: - CVE-2024-2756: Fixed bypass of security fix applied for CVE-2022-31629 that lead PHP to consider not secure cookies as secure (bsc#1222857) - CVE-2024-3096: Fixed bypass on null byte leading passwords checked via password_verify (bsc#1222858) - CVE-2024-5458: Fixed an issue that allows to bypass filters in filter_var FILTER_VALIDATE_URL. (bsc#1226073)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1222857
- https://bugzilla.suse.com/1222858
- https://bugzilla.suse.com/1226073
- https://www.suse.com/security/cve/CVE-2024-2756
- https://www.suse.com/security/cve/CVE-2024-3096
- https://www.suse.com/security/cve/CVE-2024-5458
- https://www.suse.com/support/update/announcement/2024/suse-su-20242037-1/