USN-6841-1: PHP vulnerability
Published Jun 19, 2024
·Updated
It was discovered that PHP could early return in the filtervar function resulting in invalid user information being treated as valid user information. An attacker could possibly use this issue to expose raw user input information.
Affected Software
40 affected componentsFixes available
All of the following
ubuntu/libapache2-mod-php8.3<8.3.6-0ubuntu0.24.04.1
8.3.6-0ubuntu0.24.04.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/php8.3<8.3.6-0ubuntu0.24.04.1
8.3.6-0ubuntu0.24.04.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/php8.3-cgi<8.3.6-0ubuntu0.24.04.1
8.3.6-0ubuntu0.24.04.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/php8.3-cli<8.3.6-0ubuntu0.24.04.1
8.3.6-0ubuntu0.24.04.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/php8.3-fpm<8.3.6-0ubuntu0.24.04.1
8.3.6-0ubuntu0.24.04.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libapache2-mod-php8.2<8.2.10-2ubuntu2.2
8.2.10-2ubuntu2.2
Ubuntu Ubuntu=23.10
All of the following
ubuntu/php8.2<8.2.10-2ubuntu2.2
8.2.10-2ubuntu2.2
Ubuntu Ubuntu=23.10
All of the following
ubuntu/php8.2-cgi<8.2.10-2ubuntu2.2
8.2.10-2ubuntu2.2
Ubuntu Ubuntu=23.10
All of the following
ubuntu/php8.2-cli<8.2.10-2ubuntu2.2
8.2.10-2ubuntu2.2
Ubuntu Ubuntu=23.10
All of the following
ubuntu/php8.2-fpm<8.2.10-2ubuntu2.2
8.2.10-2ubuntu2.2
Ubuntu Ubuntu=23.10
All of the following
ubuntu/libapache2-mod-php8.1<8.1.2-1ubuntu2.18
8.1.2-1ubuntu2.18
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php8.1<8.1.2-1ubuntu2.18
8.1.2-1ubuntu2.18
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php8.1-cgi<8.1.2-1ubuntu2.18
8.1.2-1ubuntu2.18
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php8.1-cli<8.1.2-1ubuntu2.18
8.1.2-1ubuntu2.18
Ubuntu Ubuntu=22.04
All of the following
ubuntu/php8.1-fpm<8.1.2-1ubuntu2.18
8.1.2-1ubuntu2.18
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libapache2-mod-php7.4<7.4.3-4ubuntu2.23
7.4.3-4ubuntu2.23
Ubuntu Ubuntu=20.04
All of the following
ubuntu/php7.4<7.4.3-4ubuntu2.23
7.4.3-4ubuntu2.23
Ubuntu Ubuntu=20.04
All of the following
ubuntu/php7.4-cgi<7.4.3-4ubuntu2.23
7.4.3-4ubuntu2.23
Ubuntu Ubuntu=20.04
All of the following
ubuntu/php7.4-cli<7.4.3-4ubuntu2.23
7.4.3-4ubuntu2.23
Ubuntu Ubuntu=20.04
All of the following
ubuntu/php7.4-fpm<7.4.3-4ubuntu2.23
7.4.3-4ubuntu2.23
Ubuntu Ubuntu=20.04
Event History
Jun 19, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6841-1?
The severity of USN-6841-1 is considered high due to the potential exposure of raw user input information.
2
How do I fix USN-6841-1?
To fix USN-6841-1, upgrade to the patched PHP versions provided in the security notice.
3
Which PHP versions are affected by USN-6841-1?
USN-6841-1 affects PHP versions 8.3, 8.2, 8.1, and 7.4 across various Ubuntu releases.
4
What are the potential consequences of USN-6841-1?
If exploited, USN-6841-1 could allow attackers to manipulate user information and bypass validation checks.
5
Is there a workaround for USN-6841-1?
There is no official workaround for USN-6841-1, and the recommended action is to apply the updates provided.