RHSA-2024:0387: Moderate: php:8.1 security update
Moderate: php:8.1 security update
Other sources
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.<br>Security Fix(es):<br><li> php: 1-byte array overrun in common path resolve code (CVE-2023-0568)</li> <li> php: DoS vulnerability when parsing multipart request body (CVE-2023-0662)</li> <li> php: Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP (CVE-2023-3247)</li> <li> php: XML loading external entity without being enabled (CVE-2023-3823)</li> <li> php: phar Buffer mismanagement (CVE-2023-3824)</li> <li> php: Passwordverify() always return true with some hash (CVE-2023-0567)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-pecl-apcuto a version that resolves this vulnerability.Fixed in 5.1.21-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-rrdto a version that resolves this vulnerability.Fixed in 2.0.3-4.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-xdebug3to a version that resolves this vulnerability.Fixed in 3.1.4-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-zipto a version that resolves this vulnerability.Fixed in 1.20.1-1.module+el9.1.0 - Upgrade
Upgrade
redhat/apcu-panelto a version that resolves this vulnerability.Fixed in 5.1.21-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-bcmathto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-clito a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-cli-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-commonto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-common-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-dbato a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-dba-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-dbgto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-debugsourceto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-develto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-embeddedto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-enchantto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-ffito a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-ffi-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-fpmto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-gdto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-gd-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-gmpto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-intlto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-intl-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-ldapto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-mbstringto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-mysqlndto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-odbcto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-opcacheto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-pdoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-pecl-apcu-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.21-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-apcu-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.21-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-apcu-develto a version that resolves this vulnerability.Fixed in 5.1.21-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-rrd-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.3-4.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-rrd-debugsourceto a version that resolves this vulnerability.Fixed in 2.0.3-4.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-xdebug3-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.4-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-xdebug3-debugsourceto a version that resolves this vulnerability.Fixed in 3.1.4-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-zip-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pecl-zip-debugsourceto a version that resolves this vulnerability.Fixed in 1.20.1-1.module+el9.1.0 - Upgrade
Upgrade
redhat/php-pgsqlto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-processto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-process-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-snmpto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-soapto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-soap-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-xmlto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
redhat/php-xml-debuginfoto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0.z+21063+f4ccb976Patch Moderate: php:8.1 security update - Upgrade
Upgrade
php-pecl-apcuto a version that resolves this vulnerability.Fixed in 5.1.21-1.module+el9.1.0.z+15477+cb86791dPatch Moderate: php:8.1 security update - Upgrade
Upgrade
php-fpmto a version that resolves this vulnerability.Fixed in 8.1.27-1.module+el9.3.0.z+21063+f4ccb976Patch Moderate: php:8.1 security update
Event History
Frequently Asked Questions
What are the security fixes in RHSA-2024:0387?
The security fixes in RHSA-2024:0387 include a 1-byte array overrun in common path resolve code (CVE-2023-0568) and a DoS vulnerability when parsing multipart requests.
How do I remediate RHSA-2024:0387?
You can remediate RHSA-2024:0387 by updating to the relevant packages as specified in the advisory, such as php version 8.1.27-1.module+el9.3.0.
What is the severity of RHSA-2024:0387?
The severity of RHSA-2024:0387 is rated as moderate.
Which versions of PHP are affected by RHSA-2024:0387?
RHSA-2024:0387 affects multiple versions of PHP, specifically those prior to version 8.1.27-1.module+el9.3.0.
What is the impact of the vulnerabilities fixed in RHSA-2024:0387?
The vulnerabilities addressed in RHSA-2024:0387 can lead to potential denial of service and exploitation through crafted inputs.