Release Info

Advisory: CLSA-2023:1680292990

OS: EL 7 PHP

Public date: 2023-03-31 00:00:00

Project: php

Version: 7.2.34-27.el7

Errata link: https://errata.cloudlinux.com/php-els/el7/CLSA-2023-1680292990.html

Changelog

- Fix for hardened PHP - CVE-2023-0567: Fix validation of malformed BCrypt hashes - CVE-2023-0568: Fix array overrun when appending slash to paths - CVE-2023-0662: Fix DOS vulnerabality by limiting number of parsed multipart body parts and printing upload limit exceed error message only once

Update

Update command: yum update alt-php*

Packages list

alt-php72-7.2.34-27.el7.x86_64.rpm alt-php72-bcmath-7.2.34-27.el7.x86_64.rpm alt-php72-cli-7.2.34-27.el7.x86_64.rpm alt-php72-common-7.2.34-27.el7.x86_64.rpm alt-php72-dba-7.2.34-27.el7.x86_64.rpm alt-php72-devel-7.2.34-27.el7.x86_64.rpm alt-php72-enchant-7.2.34-27.el7.x86_64.rpm alt-php72-firebird-7.2.34-27.el7.x86_64.rpm alt-php72-gd-7.2.34-27.el7.x86_64.rpm alt-php72-imap-7.2.34-27.el7.x86_64.rpm alt-php72-intl-7.2.34-27.el7.x86_64.rpm alt-php72-ldap-7.2.34-27.el7.x86_64.rpm alt-php72-mbstring-7.2.34-27.el7.x86_64.rpm alt-php72-mysqlnd-7.2.34-27.el7.x86_64.rpm alt-php72-odbc-7.2.34-27.el7.x86_64.rpm alt-php72-opcache-7.2.34-27.el7.x86_64.rpm alt-php72-pdo-7.2.34-27.el7.x86_64.rpm alt-php72-pgsql-7.2.34-27.el7.x86_64.rpm alt-php72-process-7.2.34-27.el7.x86_64.rpm alt-php72-pspell-7.2.34-27.el7.x86_64.rpm alt-php72-recode-7.2.34-27.el7.x86_64.rpm alt-php72-snmp-7.2.34-27.el7.x86_64.rpm alt-php72-soap-7.2.34-27.el7.x86_64.rpm alt-php72-sodium-7.2.34-27.el7.x86_64.rpm alt-php72-tidy-7.2.34-27.el7.x86_64.rpm alt-php72-xml-7.2.34-27.el7.x86_64.rpm alt-php72-xmlrpc-7.2.34-27.el7.x86_64.rpm alt-php72-zts-7.2.34-27.el7.x86_64.rpm alt-php72-zts-devel-7.2.34-27.el7.x86_64.rpm

CVEs

CVE-2023-0568
CVE-2023-0662
CVE-2023-0567