USN-6757-1: PHP vulnerabilities
It was discovered that PHP incorrectly handled PHPCLISERVERWORKERS variable. An attacker could possibly use this issue to cause a crash or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-4900) It was discovered that PHP incorrectly handled certain cookies. An attacker could possibly use this issue to cookie by pass. (CVE-2024-2756) It was discovered that PHP incorrectly handled some passwords. An attacker could possibly use this issue to cause an account takeover attack. (CVE-2024-3096)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6757-1?
The severity of USN-6757-1 is categorized as high due to the potential for remote code execution and service disruption.
How do I fix USN-6757-1?
To fix USN-6757-1, update your PHP packages to the latest versions specified in the advisory.
What versions of PHP are affected by USN-6757-1?
USN-6757-1 affects PHP versions 7.0, 7.2, 7.4, and 8.1 specifically in Ubuntu 16.04, 18.04, 20.04, and 22.04.
Is USN-6757-1 applicable to systems other than Ubuntu?
No, USN-6757-1 specifically applies to Ubuntu systems, particularly versions 16.04, 18.04, 20.04, and 22.04.
What is the CVE associated with USN-6757-1?
The CVE associated with USN-6757-1 is CVE-2022-4900, which details the vulnerability affecting PHP.