USN-6199-1: PHP vulnerability
Published Jul 3, 2023
·Updated
It was discovered that PHP incorrectly handled certain Digest authentication for SOAP. An attacker could possibly use this issue to expose sensitive information.
Affected Software
54 affected componentsFixes available
All of the following
ubuntu/php8.1-cli<8.1.12-1ubuntu4.2
8.1.12-1ubuntu4.2
Ubuntu Ubuntu=23.04
All of the following
ubuntu/php8.1<8.1.12-1ubuntu4.2
8.1.12-1ubuntu4.2
Ubuntu Ubuntu=23.04
All of the following
ubuntu/php8.1-soap<8.1.12-1ubuntu4.2
8.1.12-1ubuntu4.2
Ubuntu Ubuntu=23.04
All of the following
ubuntu/libapache2-mod-php7.4<8.1.12-1ubuntu4.2
8.1.12-1ubuntu4.2
Ubuntu Ubuntu=23.04
All of the following
ubuntu/libapache2-mod-php8.0<8.1.12-1ubuntu4.2
8.1.12-1ubuntu4.2
Ubuntu Ubuntu=23.04
All of the following
ubuntu/libapache2-mod-php8.1<8.1.12-1ubuntu4.2
8.1.12-1ubuntu4.2
Ubuntu Ubuntu=23.04
All of the following
ubuntu/php8.1-cgi<8.1.12-1ubuntu4.2
8.1.12-1ubuntu4.2
Ubuntu Ubuntu=23.04
All of the following
ubuntu/php8.1-cli<8.1.7-1ubuntu3.5
8.1.7-1ubuntu3.5
Ubuntu Ubuntu=22.10
All of the following
ubuntu/php8.1<8.1.7-1ubuntu3.5
8.1.7-1ubuntu3.5
Ubuntu Ubuntu=22.10
All of the following
ubuntu/php8.1-soap<8.1.7-1ubuntu3.5
8.1.7-1ubuntu3.5
Ubuntu Ubuntu=22.10
All of the following
ubuntu/libapache2-mod-php7.4<8.1.7-1ubuntu3.5
8.1.7-1ubuntu3.5
Ubuntu Ubuntu=22.10
All of the following
ubuntu/libapache2-mod-php8.0<8.1.7-1ubuntu3.5
8.1.7-1ubuntu3.5
Ubuntu Ubuntu=22.10
All of the following
ubuntu/libapache2-mod-php8.1<8.1.7-1ubuntu3.5
8.1.7-1ubuntu3.5
Ubuntu Ubuntu=22.10
All of the following
ubuntu/php8.1-cgi<8.1.7-1ubuntu3.5
8.1.7-1ubuntu3.5
Ubuntu Ubuntu=22.10
All of the following
ubuntu/php8.1-cli<8.1.2-1ubuntu2.13
8.1.2-1ubuntu2.13
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php8.1<8.1.2-1ubuntu2.13
8.1.2-1ubuntu2.13
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php8.1-sqlite3<8.1.2-1ubuntu2.13
8.1.2-1ubuntu2.13
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php8.1-soap<8.1.2-1ubuntu2.13
8.1.2-1ubuntu2.13
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libapache2-mod-php7.4<8.1.2-1ubuntu2.13
8.1.2-1ubuntu2.13
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libapache2-mod-php8.0<8.1.2-1ubuntu2.13
8.1.2-1ubuntu2.13
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libapache2-mod-php8.1<8.1.2-1ubuntu2.13
8.1.2-1ubuntu2.13
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php8.1-cgi<8.1.2-1ubuntu2.13
8.1.2-1ubuntu2.13
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php7.4<7.4.3-4ubuntu2.19
7.4.3-4ubuntu2.19
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libapache2-mod-php7.4<7.4.3-4ubuntu2.19
7.4.3-4ubuntu2.19
Ubuntu Ubuntu=20.04
All of the following
ubuntu/php7.4-cgi<7.4.3-4ubuntu2.19
7.4.3-4ubuntu2.19
Ubuntu Ubuntu=20.04
All of the following
ubuntu/php7.4-soap<7.4.3-4ubuntu2.19
7.4.3-4ubuntu2.19
Ubuntu Ubuntu=20.04
All of the following
ubuntu/php7.4-cli<7.4.3-4ubuntu2.19
7.4.3-4ubuntu2.19
Ubuntu Ubuntu=20.04
Event History
Jul 3, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6199-1?
The severity of USN-6199-1 is moderate.
2
What software is affected by USN-6199-1?
The affected software includes PHP versions 8.1.12-1ubuntu4.2, 8.1.7-1ubuntu3.5, 8.1.2-1ubuntu2.13, 7.4.3-4ubuntu2.19.
3
How can an attacker exploit the vulnerability described in USN-6199-1?
An attacker could exploit the vulnerability in USN-6199-1 to expose sensitive information by incorrectly handling certain Digest authentication for SOAP.
4
How can I fix the PHP vulnerability described in USN-6199-1?
To fix the vulnerability, update PHP to the latest version provided in the remedy field of the affected software section.
5
Where can I find more information about USN-6199-1?
You can find more information about USN-6199-1 on the Ubuntu Security Notices page and the referenced links.