Red Hat Security Advisory: rh-php73-php security, bug fix, and enhancement update
🔗 CVE IDs covered (14)
📋 Description
CVE-2019-11045 — php: DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte CVE-2019-11047 — php: Information disclosure in exif_read_data() CVE-2019-11048 — php: Integer wraparounds when receiving multipart forms CVE-2019-11050 — php: Out of bounds read when parsing EXIF information CVE-2019-19203 — oniguruma: Heap-based buffer over-read in function gb18030_mbc_enc_len in file gb18030.c CVE-2019-19204 — oniguruma: Heap-based buffer over-read in function fetch_interval_quantifier in regparse.c CVE-2019-19246 — oniguruma: Heap-based buffer overflow in str_lower_case_match in regexec.c CVE-2020-7059 — php: Out of bounds read in php_strip_tags_ex CVE-2020-7060 — php: Global buffer-overflow in mbfl_filt_conv_big5_wchar function CVE-2020-7062 — php: NULL pointer dereference in PHP session upload progress CVE-2020-7063 — php: Files added to tar with Phar::buildFromIterator have all-access permissions CVE-2020-7064 — php: Information disclosure in exif_read_data() function CVE-2020-7065 — php: Using mb_strtolower() function with UTF-32LE encoding leads to potential code execution CVE-2020-7066 — php: Information disclosure in function get_headers
🎯 Affected products200
- Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7)
- rh-php73-php-0:7.3.20-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-php73-php-0:7.3.20-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- rh-php73-php-0:7.3.20-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- rh-php73-php-0:7.3.20-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-php73-php-0:7.3.20-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- rh-php73-php-0:7.3.20-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- rh-php73-php-0:7.3.20-1.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-php73-php-0:7.3.20-1.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- rh-php73-php-0:7.3.20-1.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- rh-php73-php-0:7.3.20-1.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7)
- rh-php73-php-0:7.3.20-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-php73-php-0:7.3.20-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- rh-php73-php-0:7.3.20-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- rh-php73-php-0:7.3.20-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7)
- rh-php73-php-bcmath-0:7.3.20-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-php73-php-bcmath-0:7.3.20-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- rh-php73-php-bcmath-0:7.3.20-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- rh-php73-php-bcmath-0:7.3.20-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-php73-php-bcmath-0:7.3.20-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- rh-php73-php-bcmath-0:7.3.20-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- rh-php73-php-bcmath-0:7.3.20-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-php73-php-bcmath-0:7.3.20-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- rh-php73-php-bcmath-0:7.3.20-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- rh-php73-php-bcmath-0:7.3.20-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7)
- rh-php73-php-cli-0:7.3.20-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-php73-php-cli-0:7.3.20-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon must be restarted for the update to take effect. Workaround: Ensure that `post_max_size` is set to a value less than 2GB, or remains default.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2020:5275
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_software_collections/3/html/3.6_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1777537
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1786570
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1786572
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1788258
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797776
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797779
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802061
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802068
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1808532
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1808536
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820601
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820604
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820627
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1837842
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_5275.json