Release Info

Advisory: CLSA-2023:1680293974

OS: EL 6 PHP

Public date: 2023-03-31 00:00:00

Project: php

Version: 7.4.33-7.el6

Errata link: https://errata.cloudlinux.com/php-els/el6/CLSA-2023-1680293974.html

Changelog

- Fix for hardened PHP - CVE-2023-0567: Fix validation of malformed BCrypt hashes - CVE-2023-0568: Fix array overrun when appending slash to paths - CVE-2023-0662: Fix DOS vulnerabality by limiting number of parsed multipart body parts and printing upload limit exceed error message only once

Update

Update command: yum update alt-php*

Packages list

alt-php74-7.4.33-7.el6.x86_64.rpm alt-php74-bcmath-7.4.33-7.el6.x86_64.rpm alt-php74-cli-7.4.33-7.el6.x86_64.rpm alt-php74-common-7.4.33-7.el6.x86_64.rpm alt-php74-dba-7.4.33-7.el6.x86_64.rpm alt-php74-devel-7.4.33-7.el6.x86_64.rpm alt-php74-enchant-7.4.33-7.el6.x86_64.rpm alt-php74-firebird-7.4.33-7.el6.x86_64.rpm alt-php74-gd-7.4.33-7.el6.x86_64.rpm alt-php74-imap-7.4.33-7.el6.x86_64.rpm alt-php74-intl-7.4.33-7.el6.x86_64.rpm alt-php74-ldap-7.4.33-7.el6.x86_64.rpm alt-php74-mbstring-7.4.33-7.el6.x86_64.rpm alt-php74-mysqlnd-7.4.33-7.el6.x86_64.rpm alt-php74-odbc-7.4.33-7.el6.x86_64.rpm alt-php74-opcache-7.4.33-7.el6.x86_64.rpm alt-php74-pdo-7.4.33-7.el6.x86_64.rpm alt-php74-pgsql-7.4.33-7.el6.x86_64.rpm alt-php74-process-7.4.33-7.el6.x86_64.rpm alt-php74-pspell-7.4.33-7.el6.x86_64.rpm alt-php74-snmp-7.4.33-7.el6.x86_64.rpm alt-php74-soap-7.4.33-7.el6.x86_64.rpm alt-php74-sodium-7.4.33-7.el6.x86_64.rpm alt-php74-tidy-7.4.33-7.el6.x86_64.rpm alt-php74-xml-7.4.33-7.el6.x86_64.rpm alt-php74-xmlrpc-7.4.33-7.el6.x86_64.rpm

CVEs

CVE-2023-0568
CVE-2023-0662
CVE-2023-0567