Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2024.0132
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2024-0132)
Zusammenfassung:The remote host is missing an update for the 'php' package(s) announced via the MGASA-2024-0132 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'php' package(s) announced via the MGASA-2024-0132 advisory.

Vulnerability Insight:
Core:
- Corrupted memory in destructor with weak references
- GC does not scale well with a lot of objects created in destructor
DOM:
- Add some missing ZPP checks.
- Fix potential memory leak in XPath evaluation results.
FPM:
- Fix incorrect check in fpm_shm_free().
Gettext:
- Fixed sigabrt raised with dcgettext/dcngettext calls with gettext
0.22.5 with category set to LC_ALL.
MySQLnd:
- Fixed handshake response [mysqlnd]
- Fix incorrect charset length in check_mb_eucjpms().
Opcache:
- JITed QM_ASSIGN may be optimized out when op1 is null
- Segmentation fault for enabled observers when calling trait method of
internal trait when opcache is loaded
PDO:
- Fix various PDORow bugs.
Random:
- Pre-PHP 8.2 compatibility for mt_srand with unknown modes
- Global Mt19937 is not properly reset in-between requests when
MT_RAND_PHP is used
Session:
- Segfault with session_decode and compilation error
Sockets:
- socket_getsockname returns random characters in the end of the socket
name
SPL:
- Unable to resize SplfixedArray after being unserialized in PHP 8.2.15
- Unexpected null pointer in zend_string.h
Standard:
- Added validation of `\n` in $additional_headers of mail()
- Command injection via array-ish $command parameter of proc_open).
(CVE-2024-1874)
Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to
partial CVE-2022-31629 fix). (CVE-2024-2756)
- password_verify can erroneously return true, opening ATO risk.
(CVE-2024-3096)

Affected Software/OS:
'php' package(s) on Mageia 9.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2024-1874
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/
https://github.com/php/php-src/security/advisories/GHSA-pc52-254m-w9w7
http://www.openwall.com/lists/oss-security/2024/04/12/11
http://www.openwall.com/lists/oss-security/2024/06/07/1
Common Vulnerability Exposure (CVE) ID: CVE-2024-2756
https://github.com/php/php-src/security/advisories/GHSA-wpj3-hf5j-x4v4
https://lists.debian.org/debian-lts-announce/2024/05/msg00005.html
Common Vulnerability Exposure (CVE) ID: CVE-2024-3096
https://github.com/php/php-src/security/advisories/GHSA-h746-cjrr-wfmr
CopyrightCopyright (C) 2024 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.