{"schema_version":"1.7.3","id":"SUSE-SU-2022:4068-1","published":"2022-11-18T10:55:22Z","modified":"2026-02-04T02:31:07.533852Z","related":["CVE-2017-8923","CVE-2020-7068","CVE-2020-7069","CVE-2020-7070","CVE-2020-7071","CVE-2021-21702","CVE-2021-21703","CVE-2021-21704","CVE-2021-21705","CVE-2021-21706","CVE-2021-21707","CVE-2021-21708","CVE-2022-31625","CVE-2022-31626","CVE-2022-31628","CVE-2022-31629","CVE-2022-31630","CVE-2022-37454"],"upstream":["CVE-2017-8923","CVE-2020-7068","CVE-2020-7069","CVE-2020-7070","CVE-2020-7071","CVE-2021-21702","CVE-2021-21703","CVE-2021-21704","CVE-2021-21705","CVE-2021-21706","CVE-2021-21707","CVE-2021-21708","CVE-2022-31625","CVE-2022-31626","CVE-2022-31628","CVE-2022-31629","CVE-2022-31630","CVE-2022-37454"],"summary":"Security update for php74","details":"This update for php74 fixes the following issues:\n\n- Version update to 7.4.33:\n- CVE-2022-31630: Fixed out-of-bounds read due to insufficient input validation in imageloadfont() (bsc#1204979).\n- CVE-2022-37454: Fixed buffer overflow in hash_update() on long parameter (bsc#1204577).\n\n- Version update to 7.4.32 (jsc#SLE-23639)\n- CVE-2022-31628: Fixed an uncontrolled recursion in the phar uncompressor while decompressing 'quines' gzip files. (bsc#1203867)\n- CVE-2022-31629: Fixed a bug which could lead an attacker to set an insecure cookie that will treated as secure in the victim's browser. (bsc#1203870)\n","affected":[{"package":{"name":"php74","ecosystem":"SUSE:Linux Enterprise Module for Web and Scripting 12","purl":"pkg:rpm/suse/php74&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4.33-1.47.2"}]}],"ecosystem_specific":{"binaries":[{"apache2-mod_php74":"7.4.33-1.47.2","php74":"7.4.33-1.47.2","php74-bcmath":"7.4.33-1.47.2","php74-bz2":"7.4.33-1.47.2","php74-calendar":"7.4.33-1.47.2","php74-ctype":"7.4.33-1.47.2","php74-curl":"7.4.33-1.47.2","php74-dba":"7.4.33-1.47.2","php74-dom":"7.4.33-1.47.2","php74-enchant":"7.4.33-1.47.2","php74-exif":"7.4.33-1.47.2","php74-fastcgi":"7.4.33-1.47.2","php74-fileinfo":"7.4.33-1.47.2","php74-fpm":"7.4.33-1.47.2","php74-ftp":"7.4.33-1.47.2","php74-gd":"7.4.33-1.47.2","php74-gettext":"7.4.33-1.47.2","php74-gmp":"7.4.33-1.47.2","php74-iconv":"7.4.33-1.47.2","php74-intl":"7.4.33-1.47.2","php74-json":"7.4.33-1.47.2","php74-ldap":"7.4.33-1.47.2","php74-mbstring":"7.4.33-1.47.2","php74-mysql":"7.4.33-1.47.2","php74-odbc":"7.4.33-1.47.2","php74-opcache":"7.4.33-1.47.2","php74-openssl":"7.4.33-1.47.2","php74-pcntl":"7.4.33-1.47.2","php74-pdo":"7.4.33-1.47.2","php74-pgsql":"7.4.33-1.47.2","php74-phar":"7.4.33-1.47.2","php74-posix":"7.4.33-1.47.2","php74-readline":"7.4.33-1.47.2","php74-shmop":"7.4.33-1.47.2","php74-snmp":"7.4.33-1.47.2","php74-soap":"7.4.33-1.47.2","php74-sockets":"7.4.33-1.47.2","php74-sodium":"7.4.33-1.47.2","php74-sqlite":"7.4.33-1.47.2","php74-sysvmsg":"7.4.33-1.47.2","php74-sysvsem":"7.4.33-1.47.2","php74-sysvshm":"7.4.33-1.47.2","php74-tidy":"7.4.33-1.47.2","php74-tokenizer":"7.4.33-1.47.2","php74-xmlreader":"7.4.33-1.47.2","php74-xmlrpc":"7.4.33-1.47.2","php74-xmlwriter":"7.4.33-1.47.2","php74-xsl":"7.4.33-1.47.2","php74-zip":"7.4.33-1.47.2","php74-zlib":"7.4.33-1.47.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4068-1.json"}},{"package":{"name":"php74","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/php74&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4.33-1.47.2"}]}],"ecosystem_specific":{"binaries":[{"php74-devel":"7.4.33-1.47.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4068-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203867"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203870"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204577"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204979"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-8923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-7068"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-7069"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-7070"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-7071"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21702"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21704"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21705"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21706"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21707"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-31625"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-31626"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-31628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-31629"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-31630"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-37454"}]}