First published: Tue Oct 27 2020(Updated: )
USN-4583-1 fixed vulnerabilities in PHP. This update provides the corresponding update for Ubuntu 20.10. Original advisory details: It was discovered that PHP incorrectly handled certain encrypt ciphers. An attacker could possibly use this issue to decrease security or cause incorrect encryption data. (CVE-2020-7069) It was discorevered that PHP incorrectly handled certain HTTP cookies. An attacker could possibly use this issue to forge cookie which is supposed to be secure. (CVE-2020-7070)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libapache2-mod-php7.4 | <7.4.9-1ubuntu1.1 | 7.4.9-1ubuntu1.1 |
Ubuntu Ubuntu | =20.10 | |
All of | ||
ubuntu/php7.4-cgi | <7.4.9-1ubuntu1.1 | 7.4.9-1ubuntu1.1 |
Ubuntu Ubuntu | =20.10 | |
All of | ||
ubuntu/php7.4-cli | <7.4.9-1ubuntu1.1 | 7.4.9-1ubuntu1.1 |
Ubuntu Ubuntu | =20.10 | |
All of | ||
ubuntu/php7.4-curl | <7.4.9-1ubuntu1.1 | 7.4.9-1ubuntu1.1 |
Ubuntu Ubuntu | =20.10 | |
All of | ||
ubuntu/php7.4-fpm | <7.4.9-1ubuntu1.1 | 7.4.9-1ubuntu1.1 |
Ubuntu Ubuntu | =20.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this advisory is USN-4583-2.
The affected software for this vulnerability is libapache2-mod-php7.4, php7.4-cgi, php7.4-cli, php7.4-curl, and php7.4-fpm.
The severity of this vulnerability is not specified in the provided information.
To fix this vulnerability, update the affected software to version 7.4.9-1ubuntu1.1 or later.
You can find more information about this vulnerability in the references provided: https://ubuntu.com/security/CVE-2020-7070, https://ubuntu.com/security/CVE-2020-7069, and https://ubuntu.com/security/notices/USN-4583-1.