VYPR

rpm package

suse/php7&distro=SUSE Manager Server 4.2

pkg:rpm/suse/php7&distro=SUSE%20Manager%20Server%204.2

Vulnerabilities (7)

  • CVE-2022-31631Feb 12, 2025
    affected < 7.4.33-150200.3.51.1fixed 7.4.33-150200.3.51.1

    In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulner

  • CVE-2023-3824Aug 11, 2023
    affected < 7.4.33-150200.3.60.1fixed 7.4.33-150200.3.60.1

    In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.

  • CVE-2023-3823Aug 11, 2023
    affected < 7.4.33-150200.3.60.1fixed 7.4.33-150200.3.60.1

    In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes

  • CVE-2023-3247Jul 22, 2023
    affected < 7.4.33-150200.3.57.1fixed 7.4.33-150200.3.57.1

    In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication, random value generator was not checked for failure, and was using narrower range of values than it should have. In case of random generator failure, it could l

  • CVE-2023-0568Feb 16, 2023
    affected < 7.4.33-150200.3.51.1fixed 7.4.33-150200.3.51.1

    In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten w

  • CVE-2023-0662Feb 16, 2023
    affected < 7.4.33-150200.3.51.1fixed 7.4.33-150200.3.51.1

    In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or di

  • CVE-2023-0567Feb 16, 2023
    affected < 7.4.33-150200.3.51.1fixed 7.4.33-150200.3.51.1

    In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as v