UbuntuUpdates.org

Bugs fixes in "php8.1"

Origin Bug number Title Date fixed
CVE CVE-2024-9026 Logs from childrens may be altered 2024-10-01
CVE CVE-2024-8927 cgi.force_redirect configuration is byppassible due to the environment variable collision 2024-10-01
CVE CVE-2024-8925 Erroneous parsing of multipart form data 2024-10-01
CVE CVE-2024-9026 Logs from childrens may be altered 2024-10-01
CVE CVE-2024-8927 cgi.force_redirect configuration is byppassible due to the environment variable collision 2024-10-01
CVE CVE-2024-8925 Erroneous parsing of multipart form data 2024-10-01
CVE CVE-2024-9026 Logs from childrens may be altered 2024-10-01
CVE CVE-2024-8927 cgi.force_redirect configuration is byppassible due to the environment variable collision 2024-10-01
CVE CVE-2024-8925 Erroneous parsing of multipart form data 2024-10-01
CVE CVE-2024-9026 Logs from childrens may be altered 2024-10-01
CVE CVE-2024-8927 cgi.force_redirect configuration is byppassible due to the environment variable collision 2024-10-01
CVE CVE-2024-8925 Erroneous parsing of multipart form data 2024-10-01
CVE CVE-2024-5458 In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when 2024-06-19
CVE CVE-2024-5458 In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when 2024-06-19
CVE CVE-2024-5458 In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when 2024-06-19
CVE CVE-2024-5458 In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when 2024-06-19
CVE CVE-2024-3096 In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00 2024-05-03
CVE CVE-2024-2756 Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard in 2024-05-03
CVE CVE-2022-4900 A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow. 2024-05-03
CVE CVE-2024-3096 In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00 2024-05-03



About   -   Send Feedback to @ubuntu_updates