Release Info

Advisory: CLSA-2023:1695496786

OS: EL 8

Public date: 2023-09-23 15:19:48

Project: php

Version: 5.2.17-194.el8

Errata link: https://errata.tuxcare.com/els_lang_php/el8/CLSA-2023-1695496786.html

Changelog

- Fix for hardened PHP - CVE-2023-3823: Fix external entity loading in XML without enabling by sanitizing libxml2 globals before parsing - CVE-2023-3824: Fix buffer mismanagement in phar_dir_read()

Update

Update command: yum update alt-php*

Packages list

alt-php52-5.2.17-194.el8.x86_64.rpm alt-php52-bcmath-5.2.17-194.el8.x86_64.rpm alt-php52-cli-5.2.17-194.el8.x86_64.rpm alt-php52-common-5.2.17-194.el8.x86_64.rpm alt-php52-dba-5.2.17-194.el8.x86_64.rpm alt-php52-dbx-5.2.17-194.el8.x86_64.rpm alt-php52-devel-5.2.17-194.el8.x86_64.rpm alt-php52-enchant-5.2.17-194.el8.x86_64.rpm alt-php52-firebird-5.2.17-194.el8.x86_64.rpm alt-php52-gd-5.2.17-194.el8.x86_64.rpm alt-php52-imap-5.2.17-194.el8.x86_64.rpm alt-php52-intl-5.2.17-194.el8.x86_64.rpm alt-php52-ldap-5.2.17-194.el8.x86_64.rpm alt-php52-mbstring-5.2.17-194.el8.x86_64.rpm alt-php52-mcrypt-5.2.17-194.el8.x86_64.rpm alt-php52-mssql-5.2.17-194.el8.x86_64.rpm alt-php52-ncurses-5.2.17-194.el8.x86_64.rpm alt-php52-odbc-5.2.17-194.el8.x86_64.rpm alt-php52-pdo-5.2.17-194.el8.x86_64.rpm alt-php52-pgsql-5.2.17-194.el8.x86_64.rpm alt-php52-process-5.2.17-194.el8.x86_64.rpm alt-php52-pspell-5.2.17-194.el8.x86_64.rpm alt-php52-recode-5.2.17-194.el8.x86_64.rpm alt-php52-snmp-5.2.17-194.el8.x86_64.rpm alt-php52-soap-5.2.17-194.el8.x86_64.rpm alt-php52-sqlite-5.2.17-194.el8.x86_64.rpm alt-php52-sybase-5.2.17-194.el8.x86_64.rpm alt-php52-tidy-5.2.17-194.el8.x86_64.rpm alt-php52-xml-5.2.17-194.el8.x86_64.rpm alt-php52-xmlrpc-5.2.17-194.el8.x86_64.rpm

CVEs

CVE-2023-3823
CVE-2023-3824