Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.833234
Category:SuSE Local Security Checks
Title:openSUSE: Security Advisory for php8 (SUSE-SU-2022:3198-2)
Summary:The remote host is missing an update for the 'php8'; package(s) announced via the SUSE-SU-2022:3198-2 advisory.
Description:Summary:
The remote host is missing an update for the 'php8'
package(s) announced via the SUSE-SU-2022:3198-2 advisory.

Vulnerability Insight:
This update for php8-pear fixes the following issues:

- Add php8-pear to SLE15-SP4 (jsc#SLE-24728)

- Update to 1.10.21

- PEAR 1.10.13

* unsupported protocol - use --force to continue

* Add $this operator to _determineIfPowerpc calls

- Update to 1.10.20

- Archive_Tar 1.4.14

* Properly fix symbolic link path traversal (CVE-2021-32610)

- Archive_Tar 1.4.13

* Relative symlinks failing (out-of path file extraction)

- Archive_Tar 1.4.12

- Archive_Tar 1.4.11

- provides and obsoletes php7-pear-Archive_Tar, former location
of PEAR/Archive/Tar.php

- Update to version 1.10.19

- PEAR 1.10.12

* adjust dependencies based on new releases

- XML_Util 1.4.5

* fix Trying to access array offset on value of type int

- Update to version 1.10.18

- Remove pear-cacheid-array-check.patch (upstreamed)

- Contents of .filemap are now sorted internally

- Sort contents of .filemap to make build reproducible

- Recommend php7-openssl to allow https sources to be used

- Modify metadata_dir for system configuration only

- Add /var/lib/pear directory where xml files are stored

- Cleanup %files section

- Only use the GPG keys of Chuck Burgess. Extracted from the Release
Manager public keys.

- Add release versions of PEAR modules

- Install metadata files (registry, filemap, channels, ...) in
/var/lib/pear/ instead of /usr/share/php7/PEAR/

- Update to version 1.10.17

Affected Software/OS:
'php8' package(s) on openSUSE Leap 15.4.

Solution:
Please install the updated package(s).

CVSS Score:
3.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-32610
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42GPGVVFTLJYAKRI75IVB5R45NYQGEUR/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G5LTY6COQYNMMHQJ3QIOJHEWCKD4XDFH/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VJQQYDAOWHD6RDITDRPHFW7WY6BS3V5N/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CAODVMHGL5MHQWQAQTXQ7G7OE3VQZ7LS/
https://github.com/pear/Archive_Tar/commit/7789ebb2f34f9e4adb3a4152ad0d1548930a9755
https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4f
https://github.com/pear/Archive_Tar/releases/tag/1.4.14
https://lists.debian.org/debian-lts-announce/2021/07/msg00023.html
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.