Release Info

Advisory: CLSA-2023:1680289050

OS: EL 6 PHP

Public date: 2023-03-31 00:00:00

Project: php

Version: 5.3.29-160.el6

Errata link: https://errata.cloudlinux.com/php-els/el6/CLSA-2023-1680289050.html

Changelog

- Fix for hardened PHP - CVE-2023-0567: Fix validation of malformed BCrypt hashes - CVE-2023-0568: Fix array overrun when appending slash to paths - CVE-2023-0662: Fix DOS vulnerabality by limiting number of parsed multipart body parts and printing upload limit exceed error message only once

Update

Update command: yum update alt-php*

Packages list

alt-php53-5.3.29-160.el6.x86_64.rpm alt-php53-bcmath-5.3.29-160.el6.x86_64.rpm alt-php53-cli-5.3.29-160.el6.x86_64.rpm alt-php53-common-5.3.29-160.el6.x86_64.rpm alt-php53-dba-5.3.29-160.el6.x86_64.rpm alt-php53-dbx-5.3.29-160.el6.x86_64.rpm alt-php53-devel-5.3.29-160.el6.x86_64.rpm alt-php53-enchant-5.3.29-160.el6.x86_64.rpm alt-php53-firebird-5.3.29-160.el6.x86_64.rpm alt-php53-gd-5.3.29-160.el6.x86_64.rpm alt-php53-imap-5.3.29-160.el6.x86_64.rpm alt-php53-intl-5.3.29-160.el6.x86_64.rpm alt-php53-ldap-5.3.29-160.el6.x86_64.rpm alt-php53-mbstring-5.3.29-160.el6.x86_64.rpm alt-php53-mcrypt-5.3.29-160.el6.x86_64.rpm alt-php53-mssql-5.3.29-160.el6.x86_64.rpm alt-php53-mysqlnd-5.3.29-160.el6.x86_64.rpm alt-php53-odbc-5.3.29-160.el6.x86_64.rpm alt-php53-pdo-5.3.29-160.el6.x86_64.rpm alt-php53-pgsql-5.3.29-160.el6.x86_64.rpm alt-php53-process-5.3.29-160.el6.x86_64.rpm alt-php53-pspell-5.3.29-160.el6.x86_64.rpm alt-php53-recode-5.3.29-160.el6.x86_64.rpm alt-php53-snmp-5.3.29-160.el6.x86_64.rpm alt-php53-soap-5.3.29-160.el6.x86_64.rpm alt-php53-sqlite-5.3.29-160.el6.x86_64.rpm alt-php53-sybase-5.3.29-160.el6.x86_64.rpm alt-php53-tidy-5.3.29-160.el6.x86_64.rpm alt-php53-xml-5.3.29-160.el6.x86_64.rpm alt-php53-xmlrpc-5.3.29-160.el6.x86_64.rpm

CVEs

CVE-2023-0567
CVE-2023-0662
CVE-2023-0568