RHSA-2020:3662: Moderate: php:7.3 security, bug fix, and enhancement update
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.The following packages have been upgraded to a later upstream version: php (7.3.20). (BZ#1856655)Security Fix(es): php: Out-of-bounds read due to integer overflow in iconvmimedecodeheaders() (CVE-2019-11039) php: Buffer over-read in exifreaddata() (CVE-2019-11040) php: DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte (CVE-2019-11045) php: Information disclosure in exifreaddata() (CVE-2019-11047) php: Integer wraparounds when receiving multipart forms (CVE-2019-11048) oniguruma: Use-after-free in onignewdeluxe() in regext.c (CVE-2019-13224) oniguruma: NULL pointer dereference in matchat() in regexec.c (CVE-2019-13225) oniguruma: Stack exhaustion in regcomp.c because of recursion in regparse.c (CVE-2019-16163) oniguruma: Heap-based buffer over-read in function gb18030mbcenclen in file gb18030.c (CVE-2019-19203) oniguruma: Heap-based buffer over-read in function fetchintervalquantifier in regparse.c (CVE-2019-19204) pcre: Out of bounds read in JIT mode when \X is used in non-UTF mode (CVE-2019-20454) php: Out of bounds read in phpstriptagsex (CVE-2020-7059) php: Global buffer-overflow in mbflfiltconvbig5wchar function (CVE-2020-7060) php: NULL pointer dereference in PHP session upload progress (CVE-2020-7062) php: Files added to tar with Phar::buildFromIterator have all-access permissions (CVE-2020-7063) php: Information disclosure in exifreaddata() function (CVE-2020-7064) php: Using mbstrtolower() function with UTF-32LE encoding leads to potential code execution (CVE-2020-7065) php: Heap buffer over-read in exifscanthumbnail() (CVE-2019-11041) php: Heap buffer over-read in exifprocessusercomment() (CVE-2019-11042) php: Out of bounds read when parsing EXIF information (CVE-2019-11050) oniguruma: Heap-based buffer overflow in strlowercasematch in regexec.c (CVE-2019-19246) php: Information disclosure in function getheaders (CVE-2020-7066) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libzipto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-pearto a version that resolves this vulnerability.Fixed in 1.10.9-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/php-pecl-apcuto a version that resolves this vulnerability.Fixed in 5.1.17-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/php-pecl-rrdto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.2.0+4968+1d5097db - Upgrade
Upgrade
redhat/php-pecl-xdebugto a version that resolves this vulnerability.Fixed in 2.8.0-1.module+el8.2.0+4968+1d5097db - Upgrade
Upgrade
redhat/php-pecl-zipto a version that resolves this vulnerability.Fixed in 1.15.4-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/apcu-panelto a version that resolves this vulnerability.Fixed in 5.1.17-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/libzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/libzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/libzip-develto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/libzip-toolsto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/libzip-tools-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/php-bcmathto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-clito a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-cli-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-commonto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-common-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-dbato a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-dba-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-dbgto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-debugsourceto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-develto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-embeddedto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-enchantto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-fpmto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-gdto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-gd-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-gmpto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-intlto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-intl-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-jsonto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-json-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-ldapto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-mbstringto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-mysqlndto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-odbcto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-opcacheto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-pdoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-pecl-apcu-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.17-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/php-pecl-apcu-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.17-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/php-pecl-apcu-develto a version that resolves this vulnerability.Fixed in 5.1.17-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/php-pecl-rrd-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.2.0+4968+1d5097db - Upgrade
Upgrade
redhat/php-pecl-rrd-debugsourceto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.2.0+4968+1d5097db - Upgrade
Upgrade
redhat/php-pecl-xdebug-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.0-1.module+el8.2.0+4968+1d5097db - Upgrade
Upgrade
redhat/php-pecl-xdebug-debugsourceto a version that resolves this vulnerability.Fixed in 2.8.0-1.module+el8.2.0+4968+1d5097db - Upgrade
Upgrade
redhat/php-pecl-zip-debuginfoto a version that resolves this vulnerability.Fixed in 1.15.4-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/php-pecl-zip-debugsourceto a version that resolves this vulnerability.Fixed in 1.15.4-1.module+el8.1.0+3189+a1bff096 - Upgrade
Upgrade
redhat/php-pgsqlto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-processto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-process-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-recodeto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-recode-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-snmpto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-soapto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-soap-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-xmlto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-xml-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-xmlrpcto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/php-xmlrpc-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef - Upgrade
Upgrade
redhat/libzipto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/libzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/libzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/libzip-develto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/libzip-toolsto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/libzip-tools-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.2-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-bcmathto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-bcmath-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-clito a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-cli-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-commonto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-common-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-dbato a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-dba-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-dbgto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-dbg-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-debugsourceto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-develto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-embeddedto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-embedded-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-enchantto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-enchant-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-fpmto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-fpm-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-gdto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-gd-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-gmpto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-gmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-intlto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-intl-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-jsonto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-json-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-ldapto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-ldap-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-mbstringto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-mbstring-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-mysqlndto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-mysqlnd-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-odbcto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-odbc-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-opcacheto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-opcache-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-pdoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-pdo-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-pecl-apcuto a version that resolves this vulnerability.Fixed in 5.1.17-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/php-pecl-apcu-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.17-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/php-pecl-apcu-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.17-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/php-pecl-apcu-develto a version that resolves this vulnerability.Fixed in 5.1.17-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/php-pecl-rrdto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.2.0+4968+1d5097db.aa - Upgrade
Upgrade
redhat/php-pecl-rrd-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.2.0+4968+1d5097db.aa - Upgrade
Upgrade
redhat/php-pecl-rrd-debugsourceto a version that resolves this vulnerability.Fixed in 2.0.1-1.module+el8.2.0+4968+1d5097db.aa - Upgrade
Upgrade
redhat/php-pecl-xdebugto a version that resolves this vulnerability.Fixed in 2.8.0-1.module+el8.2.0+4968+1d5097db.aa - Upgrade
Upgrade
redhat/php-pecl-xdebug-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.0-1.module+el8.2.0+4968+1d5097db.aa - Upgrade
Upgrade
redhat/php-pecl-xdebug-debugsourceto a version that resolves this vulnerability.Fixed in 2.8.0-1.module+el8.2.0+4968+1d5097db.aa - Upgrade
Upgrade
redhat/php-pecl-zipto a version that resolves this vulnerability.Fixed in 1.15.4-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/php-pecl-zip-debuginfoto a version that resolves this vulnerability.Fixed in 1.15.4-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/php-pecl-zip-debugsourceto a version that resolves this vulnerability.Fixed in 1.15.4-1.module+el8.1.0+3189+a1bff096.aa - Upgrade
Upgrade
redhat/php-pgsqlto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-processto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-process-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-recodeto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-recode-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-snmpto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-soapto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-soap-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-xmlto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-xml-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-xmlrpcto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
redhat/php-xmlrpc-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.20-1.module+el8.2.0+7373+b272fdef.aa - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 7.3.20Patch BZ#1856655 - Operational
After installing the updated packages, restart the httpd daemon for the update to take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3662?
The severity of RHSA-2020:3662 is categorized as important.
How do I fix RHSA-2020:3662?
To fix RHSA-2020:3662, you need to upgrade the affected PHP packages to version 7.3.20 or later.
What vulnerabilities are addressed in RHSA-2020:3662?
RHSA-2020:3662 addresses an out-of-bounds read vulnerability due to integer overflow in the php iconv_mime_decode function.
Which PHP versions are affected by RHSA-2020:3662?
RHSA-2020:3662 affects PHP version 7.3.19 and prior releases.
Are there any backup precautions recommended before applying RHSA-2020:3662?
It is recommended to backup your current PHP configuration and applications before applying the updates in RHSA-2020:3662.