Ubuntu Security Update USN-7049-3: PHP vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,834
Reaction score
74
Credits
-1,257
USN-7049-1 fixed vulnerabilities in PHP. This update provides the corresponding updates for Ubuntu 14.04 LTS. Original advisory details: It was discovered that PHP incorrectly handled parsing multipart form data.A remote attacker could possibly use this issue to inject payloads and cause PHP to ignore legitimate data. (CVE-2024-8925) It was discovered that PHP incorrectly handled the cgi.force_redirect configuration option due to environment variable collisions. In certain configurations, an attacker could possibly use this issue bypass force_redirect restrictions. (CVE-2024-8927)

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top