[CLSA-2022:1659647342] Fix of 21 CVEs
Type:
security
Severity:
Critical
Release date:
2022-08-04 21:09:02 UTC
Description:
- CVE-2021-21703: fix error in php fpm shared memory organization leading to privilage escalation - CVE-2021-21707: fix handling of paths with percent encoded NULL byte - Fix bug #80672: Null Dereference in SoapClient. (CVE-2021-21702) - Fix bug #79699: PHP parses encoded cookie names so malicious `__Host-` cookies can be sent (CVE-2020-7070) - Fix bug #78875: Long variables cause OOM and temp files are not cleaned (CVE-2019-11048) - Fix bug #78876: Long variables in multipart/form-data cause OOM and temp files are not cleaned (CVE-2019-11048) - Fix bug #79465: OOB Read in urldecode() (CVE-2020-7067) - Fix bug #79282: Use-of-uninitialized-value in exif (CVE-2020-7064) - Fix bug #79329: get_headers silently truncates after a null byte (CVE-2020-7066) - Fix bug #79037: global buffer-overflow in `mbfl_filt_conv_big5_wchar` (CVE-2020-7060) - Fix bug #79082: Files added to tar with Phar::buildFromIterator have all-access permissions (CVE-2020-7063) - Fix bug #79099: OOB read in php_strip_tags_ex (CVE-2020-7059) - Fix bug #79221: Null Pointer Dereference in PHP Session Upload Progress (CVE-2020-7062) - Fixed bug #78878 (Buffer underflow in bc_shift_addsub). (CVE-2019-11046) - Fixed bug #78910 (Heap-buffer-overflow READ in exif). (CVE-2019-11047) - Fixed bug #78863 (DirectoryIterator class silently truncates after a nullbyte). (CVE-2019-11045) - Fix bug #78599 (env_path_info underflow can lead to RCE) (CVE-2019-11043) - Fixed CVE-2019-13224 - Fix bug #79797: Use of freed hash key in the phar_parse_zipfile function (CVE-2020-7068) - Fixed bug #78862 (link() silently truncates after a null byte on Windows). (CVE-2019-11044) - Fix bug #79601: Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV (CVE-2020-7069)
Updated packages:
  • alt-php56_5.6.40-65.1_amd64.deb
    sha:715eab29aa3d3e8b59f5f1c22dad0aa6d2105810
  • alt-php70_7.0.33-66.2_amd64.deb
    sha:0c43a73eddfbfaea589c33c392c7cf5cf436f409
  • alt-php71_7.1.33-34.2_amd64.deb
    sha:924d1d0ca7b81535f7ac4c27869a129fb9d3814a
  • alt-php72_7.2.34-19.2_amd64.deb
    sha:3bc7581dbac39bf10d75fb882f17be373a6b45ab
  • alt-php73_7.3.33-5.1_amd64.deb
    sha:74cf9ee3b87f730d906081998f705c7647666c1b
  • alt-php74_7.4.30-1_amd64.deb
    sha:ebacdffd8fe5979500be78d6150d29cf2fdcb531
  • alt-php80_8.0.21-1_amd64.deb
    sha:83b549c525fb4e7de0e00c35226596c9ab017cb9
  • alt-php81_8.1.8-1_amd64.deb
    sha:4df01997d8216dfbb09043b848e330e8c43a53da
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.