Release Info

Advisory: CLSA-2023:1680540020

OS: EL 9 PHP

Public date: 2023-04-03 00:00:00

Project: php

Version: 5.6.40-73.el9

Errata link: https://errata.cloudlinux.com/php-els/el9/CLSA-2023-1680540020.html

Changelog

- Fix for hardened PHP - CVE-2023-0567: Fix validation of malformed BCrypt hashes - CVE-2023-0568: Fix array overrun when appending slash to paths - CVE-2023-0662: Fix DOS vulnerabality by limiting number of parsed multipart body parts and printing upload limit exceed error message only once

Update

Update command: yum update alt-php*

Packages list

alt-php56-5.6.40-73.el9.x86_64.rpm alt-php56-bcmath-5.6.40-73.el9.x86_64.rpm alt-php56-cli-5.6.40-73.el9.x86_64.rpm alt-php56-common-5.6.40-73.el9.x86_64.rpm alt-php56-dba-5.6.40-73.el9.x86_64.rpm alt-php56-dbx-5.6.40-73.el9.x86_64.rpm alt-php56-devel-5.6.40-73.el9.x86_64.rpm alt-php56-enchant-5.6.40-73.el9.x86_64.rpm alt-php56-firebird-5.6.40-73.el9.x86_64.rpm alt-php56-gd-5.6.40-73.el9.x86_64.rpm alt-php56-imap-5.6.40-73.el9.x86_64.rpm alt-php56-intl-5.6.40-73.el9.x86_64.rpm alt-php56-ldap-5.6.40-73.el9.x86_64.rpm alt-php56-mbstring-5.6.40-73.el9.x86_64.rpm alt-php56-mcrypt-5.6.40-73.el9.x86_64.rpm alt-php56-mssql-5.6.40-73.el9.x86_64.rpm alt-php56-mysqlnd-5.6.40-73.el9.x86_64.rpm alt-php56-odbc-5.6.40-73.el9.x86_64.rpm alt-php56-pdo-5.6.40-73.el9.x86_64.rpm alt-php56-pgsql-5.6.40-73.el9.x86_64.rpm alt-php56-process-5.6.40-73.el9.x86_64.rpm alt-php56-pspell-5.6.40-73.el9.x86_64.rpm alt-php56-recode-5.6.40-73.el9.x86_64.rpm alt-php56-snmp-5.6.40-73.el9.x86_64.rpm alt-php56-soap-5.6.40-73.el9.x86_64.rpm alt-php56-sybase-5.6.40-73.el9.x86_64.rpm alt-php56-tidy-5.6.40-73.el9.x86_64.rpm alt-php56-xml-5.6.40-73.el9.x86_64.rpm alt-php56-xmlrpc-5.6.40-73.el9.x86_64.rpm

CVEs

CVE-2023-0568
CVE-2023-0662
CVE-2023-0567