USN-6670-1: php-guzzlehttp-psr7 vulnerabilities
Published Feb 29, 2024
·Updated
It was discovered that php-guzzlehttp-psr7 incorrectly parsed HTTP headers. A remote attacker could possibly use these issues to perform an HTTP header injection attack.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/php-guzzlehttp-psr7<1.8.3-1ubuntu0.1~esm1
1.8.3-1ubuntu0.1~esm1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php-guzzlehttp-psr7<1.4.2-0.1+deb10u2build0.20.04.1
1.4.2-0.1+deb10u2build0.20.04.1
Ubuntu Ubuntu=20.04
Event History
Feb 29, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6670-1?
The severity of USN-6670-1 is categorized as a potential HTTP header injection vulnerability.
2
How do I fix USN-6670-1?
To fix USN-6670-1, you should update the php-guzzlehttp-psr7 package to version 1.8.3-1ubuntu0.1~esm1 for Ubuntu 22.04 or version 1.4.2-0.1+deb10u2build0.20.04.1 for Ubuntu 20.04.
3
What systems are affected by USN-6670-1?
USN-6670-1 affects the php-guzzlehttp-psr7 package on Ubuntu versions 20.04 and 22.04.
4
Can USN-6670-1 be exploited remotely?
Yes, a remote attacker could potentially exploit USN-6670-1 to perform an HTTP header injection attack.
5
What are the potential impacts of USN-6670-1?
The potential impacts of USN-6670-1 include unauthorized actions or data breaches resulting from HTTP header injection.