Bug 13297

Summary: [CVE 21] php 7.4.30 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: critical    
Priority: High CC: a.proklov, pastordidi, s.matveev, v.potapov, y.tumanov
Version: AllFlags: v.potapov: qa_verified+
y.tumanov: secteam_verified+
a.proklov: published+
Target Milestone: 2021.1 Fresh R12   
Hardware: All   
OS: Linux   
URL: CVE-2022-31628, CVE-2022-31629, CVE-2022-31630, CVE-2022-37454,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-05-03 18:01:51 MSK
Please patch CVEs for package php version 7.4.30
  
INFO (CVEs are): php 7.4.30
 cves found
CVE-2022-31628
Desc: In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-31628
Severity: MEDIUM
CVE-2022-31629
Desc: In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-31629
Severity: MEDIUM
CVE-2022-31630
Desc: In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-31630
Severity: HIGH
CVE-2022-37454
Desc: The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-37454
Severity: CRITICAL
Comment 1 Svyatoslav Matveev 2023-05-23 10:04:40 MSK
********** QA ADVISORY **********

CVE-2022-31630 исправлено в этой версии,
остальное закрыто патчами.

*** php7

https://abf.io/build_lists/4443043
https://abf.io/build_lists/4443044
https://abf.io/build_lists/4443042
https://abf.io/build_lists/4443046
Comment 2 Dmitry Postnikov 2023-05-23 21:34:23 MSK
***************************
The update sent to testings
Comment 3 Vladimir Potapov 2023-05-30 18:28:36 MSK
php-7.4.30-3
https://abf.io/build_lists/4443043
https://abf.io/build_lists/4443044
https://abf.io/build_lists/4443042
https://abf.io/build_lists/4443046
************************* Advisory ************************
CVEs fix
***********************************************************
QA Verified
Comment 4 Yury 2023-07-25 16:31:47 MSK
Secteam Verified