Release Info

Advisory: CLSA-2022:1668727418

OS: EL 6 PHP

Public date: 2022-11-17 00:00:00

Project: php

Version: 7.3.33-7.el6

Errata link: https://errata.cloudlinux.com/php-els/el6/CLSA-2022-1668727418.html

Changelog

- Fix for harden PHP - CVE-2022-31628: Fix potential infinite recursion in phar wrapper when using quine gzip file - CVE-2022-31629: Add cookie integrity validation

Update

Update command: yum update alt-php*

Packages list

alt-php73-7.3.33-7.el6.x86_64.rpm alt-php73-bcmath-7.3.33-7.el6.x86_64.rpm alt-php73-cli-7.3.33-7.el6.x86_64.rpm alt-php73-common-7.3.33-7.el6.x86_64.rpm alt-php73-dba-7.3.33-7.el6.x86_64.rpm alt-php73-devel-7.3.33-7.el6.x86_64.rpm alt-php73-enchant-7.3.33-7.el6.x86_64.rpm alt-php73-firebird-7.3.33-7.el6.x86_64.rpm alt-php73-gd-7.3.33-7.el6.x86_64.rpm alt-php73-imap-7.3.33-7.el6.x86_64.rpm alt-php73-intl-7.3.33-7.el6.x86_64.rpm alt-php73-ldap-7.3.33-7.el6.x86_64.rpm alt-php73-mbstring-7.3.33-7.el6.x86_64.rpm alt-php73-mysqlnd-7.3.33-7.el6.x86_64.rpm alt-php73-odbc-7.3.33-7.el6.x86_64.rpm alt-php73-opcache-7.3.33-7.el6.x86_64.rpm alt-php73-pdo-7.3.33-7.el6.x86_64.rpm alt-php73-pgsql-7.3.33-7.el6.x86_64.rpm alt-php73-process-7.3.33-7.el6.x86_64.rpm alt-php73-pspell-7.3.33-7.el6.x86_64.rpm alt-php73-recode-7.3.33-7.el6.x86_64.rpm alt-php73-snmp-7.3.33-7.el6.x86_64.rpm alt-php73-soap-7.3.33-7.el6.x86_64.rpm alt-php73-sodium-7.3.33-7.el6.x86_64.rpm alt-php73-tidy-7.3.33-7.el6.x86_64.rpm alt-php73-xml-7.3.33-7.el6.x86_64.rpm alt-php73-xmlrpc-7.3.33-7.el6.x86_64.rpm

CVEs

CVE-2022-31628
CVE-2022-31629