RHSA-2020:1624: Moderate: php:7.2 security, bug fix, and enhancement update
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.The following packages have been upgraded to a later upstream version: php (7.2.24). (BZ#1726981)Security Fix(es): php: Invalid memory access in function xmlrpcdecode() (CVE-2019-9020) php: File rename across filesystems may allow unwanted access during processing (CVE-2019-9637) php: Uninitialized read in exifprocessIFDinMAKERNOTE (CVE-2019-9638) php: Uninitialized read in exifprocessIFDinMAKERNOTE (CVE-2019-9639) php: Invalid read in exifprocessSOFn() (CVE-2019-9640) php: Out-of-bounds read due to integer overflow in iconvmimedecodeheaders() (CVE-2019-11039) php: Buffer over-read in exifreaddata() (CVE-2019-11040) php: Buffer over-read in PHAR reading functions (CVE-2018-20783) php: Heap-based buffer over-read in PHAR reading functions (CVE-2019-9021) php: memcpy with negative length via crafted DNS response (CVE-2019-9022) php: Heap-based buffer over-read in mbstring regular expression functions (CVE-2019-9023) php: Out-of-bounds read in base64decodexmlrpc in ext/xmlrpc/libxmlrpc/base64.c (CVE-2019-9024) php: Heap buffer overflow in function exifprocessIFDTAG() (CVE-2019-11034) php: Heap buffer overflow in function exifiifaddvalue() (CVE-2019-11035) php: Buffer over-read in exifprocessIFDTAG() leading to information disclosure (CVE-2019-11036) php: Heap buffer over-read in exifscanthumbnail() (CVE-2019-11041) php: Heap buffer over-read in exifprocessusercomment() (CVE-2019-11042) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.2 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libzipto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-pearto a version that resolves this vulnerability.Fixed in 1.10.5-9.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/php-pecl-apcuto a version that resolves this vulnerability.Fixed in 5.1.12-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/php-pecl-zipto a version that resolves this vulnerability.Fixed in 1.15.3-1.module+el8.1.0+3186+20164e6f - Upgrade
Upgrade
redhat/apcu-panelto a version that resolves this vulnerability.Fixed in 5.1.12-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/libzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/libzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/libzip-develto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/libzip-toolsto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/libzip-tools-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/php-bcmathto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-clito a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-cli-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-commonto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-common-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-dbato a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-dba-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-dbgto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-debugsourceto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-develto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-embeddedto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-enchantto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-fpmto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-gdto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-gd-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-gmpto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-intlto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-intl-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-jsonto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-json-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-ldapto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-mbstringto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-mysqlndto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-odbcto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-opcacheto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-pdoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-pecl-apcu-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.12-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/php-pecl-apcu-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.12-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/php-pecl-apcu-develto a version that resolves this vulnerability.Fixed in 5.1.12-2.module+el8.1.0+3202+af5476b9 - Upgrade
Upgrade
redhat/php-pecl-zip-debuginfoto a version that resolves this vulnerability.Fixed in 1.15.3-1.module+el8.1.0+3186+20164e6f - Upgrade
Upgrade
redhat/php-pecl-zip-debugsourceto a version that resolves this vulnerability.Fixed in 1.15.3-1.module+el8.1.0+3186+20164e6f - Upgrade
Upgrade
redhat/php-pgsqlto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-processto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-process-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-recodeto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-recode-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-snmpto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-soapto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-soap-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-xmlto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-xml-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-xmlrpcto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/php-xmlrpc-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223 - Upgrade
Upgrade
redhat/libzipto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/libzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/libzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/libzip-develto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/libzip-toolsto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/libzip-tools-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-bcmathto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-clito a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-cli-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-commonto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-common-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-dbato a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-dba-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-dbgto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-debugsourceto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-develto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-embeddedto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-enchantto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-fpmto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-gdto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-gd-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-gmpto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-intlto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-intl-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-jsonto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-json-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-ldapto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-mbstringto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-mysqlndto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-odbcto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-opcacheto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-pdoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-pecl-apcuto a version that resolves this vulnerability.Fixed in 5.1.12-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/php-pecl-apcu-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.12-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/php-pecl-apcu-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.12-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/php-pecl-apcu-develto a version that resolves this vulnerability.Fixed in 5.1.12-2.module+el8.1.0+3202+af5476b9.aa - Upgrade
Upgrade
redhat/php-pecl-zipto a version that resolves this vulnerability.Fixed in 1.15.3-1.module+el8.1.0+3186+20164e6f.aa - Upgrade
Upgrade
redhat/php-pecl-zip-debuginfoto a version that resolves this vulnerability.Fixed in 1.15.3-1.module+el8.1.0+3186+20164e6f.aa - Upgrade
Upgrade
redhat/php-pecl-zip-debugsourceto a version that resolves this vulnerability.Fixed in 1.15.3-1.module+el8.1.0+3186+20164e6f.aa - Upgrade
Upgrade
redhat/php-pgsqlto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-processto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-process-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-recodeto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-recode-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-snmpto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-soapto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-soap-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-xmlto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-xml-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-xmlrpcto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
redhat/php-xmlrpc-debuginfoto a version that resolves this vulnerability.Fixed in 7.2.24-1.module+el8.2.0+4601+7c76a223.aa - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 7.2.24 - Operational
After installing the updated packages for BZ#1726981, restart the httpd daemon for the update to take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1624?
The severity of RHSA-2020:1624 is classified as important.
How do I fix RHSA-2020:1624?
To fix RHSA-2020:1624, you should upgrade to the latest version of the affected packages as indicated in the advisory.
What vulnerability does RHSA-2020:1624 address?
RHSA-2020:1624 addresses a vulnerability in the PHP package related to invalid memory access in the xmlrpc_decode() function.
Which packages are affected by RHSA-2020:1624?
The affected packages in RHSA-2020:1624 include php, php-bcmath, php-pear, and libzip along with their respective debug versions.
When was RHSA-2020:1624 released?
RHSA-2020:1624 was released on September 24, 2020.