Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-6199-1

Ubuntu Security Notice 6199-1 - It was discovered that PHP incorrectly handled certain Digest authentication for SOAP. An attacker could possibly use this issue to expose sensitive information.

Packet Storm
#sql#vulnerability#ubuntu#apache#php#auth

==========================================================================
Ubuntu Security Notice USN-6199-1
July 03, 2023

php7.4, php8.1 vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 23.04
  • Ubuntu 22.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Summary:

PHP could be made to expose sensitive information.

Software Description:

  • php8.1: HTML-embedded scripting language interpreter
  • php7.4: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled certain Digest
authentication for SOAP. An attacker could possibly use this issue
to expose sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.04:
libapache2-mod-php7.4 8.1.12-1ubuntu4.2
libapache2-mod-php8.0 8.1.12-1ubuntu4.2
libapache2-mod-php8.1 8.1.12-1ubuntu4.2
php8.1 8.1.12-1ubuntu4.2
php8.1-cgi 8.1.12-1ubuntu4.2
php8.1-cli 8.1.12-1ubuntu4.2
php8.1-soap 8.1.12-1ubuntu4.2

Ubuntu 22.10:
libapache2-mod-php7.4 8.1.7-1ubuntu3.5
libapache2-mod-php8.0 8.1.7-1ubuntu3.5
libapache2-mod-php8.1 8.1.7-1ubuntu3.5
php8.1 8.1.7-1ubuntu3.5
php8.1-cgi 8.1.7-1ubuntu3.5
php8.1-cli 8.1.7-1ubuntu3.5
php8.1-soap 8.1.7-1ubuntu3.5

Ubuntu 22.04 LTS:
libapache2-mod-php7.4 8.1.2-1ubuntu2.13
libapache2-mod-php8.0 8.1.2-1ubuntu2.13
libapache2-mod-php8.1 8.1.2-1ubuntu2.13
php8.1 8.1.2-1ubuntu2.13
php8.1-cgi 8.1.2-1ubuntu2.13
php8.1-cli 8.1.2-1ubuntu2.13
php8.1-soap 8.1.2-1ubuntu2.13
php8.1-sqlite3 8.1.2-1ubuntu2.13

Ubuntu 20.04 LTS:
libapache2-mod-php7.4 7.4.3-4ubuntu2.19
php7.4 7.4.3-4ubuntu2.19
php7.4-cgi 7.4.3-4ubuntu2.19
php7.4-cli 7.4.3-4ubuntu2.19
php7.4-soap 7.4.3-4ubuntu2.19

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6199-1
CVE-2023-3247

Package Information:
https://launchpad.net/ubuntu/+source/php8.1/8.1.12-1ubuntu4.2
https://launchpad.net/ubuntu/+source/php8.1/8.1.7-1ubuntu3.5
https://launchpad.net/ubuntu/+source/php8.1/8.1.2-1ubuntu2.13
https://launchpad.net/ubuntu/+source/php7.4/7.4.3-4ubuntu2.19

Related news

Red Hat Security Advisory 2024-0387-03

Red Hat Security Advisory 2024-0387-03 - An update for the php:8.1 module is now available for Red Hat Enterprise Linux 9. Issues addressed include a denial of service vulnerability.

Ubuntu Security Notice USN-6199-2

Ubuntu Security Notice 6199-2 - USN-6199-1 fixed a vulnerability in PHP. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. It was discovered that PHP incorrectly handled certain Digest authentication for SOAP. An attacker could possibly use this issue to expose sensitive information.

CVE-2023-22130: Oracle Critical Patch Update Advisory - October 2023

Vulnerability in the Sun ZFS Storage Appliance product of Oracle Systems (component: Core). The supported version that is affected is 8.8.60. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Sun ZFS Storage Appliance. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-3247: Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP

In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication, random value generator was not checked for failure, and was using narrower range of values than it should have. In case of random generator failure, it could lead to a disclosure of 31 bits of uninitialized memory from the client to the server, and it also made easier to a malicious server to guess the client's nonce. 

Packet Storm: Latest News

Ivanti EPM Agent Portal Command Execution