{"schema_version":"1.7.3","id":"SUSE-SU-2023:0515-1","published":"2023-02-24T14:27:04Z","modified":"2026-02-04T04:10:40.832889Z","related":["CVE-2023-0567","CVE-2023-0568","CVE-2023-0662"],"upstream":["CVE-2023-0567","CVE-2023-0568","CVE-2023-0662"],"summary":"Security update for php74","details":"This update for php74 fixes the following issues:\n\n  - CVE-2023-0568: Fixed NULL byte off-by-one in php_check_specific_open_basedir (bnc#1208366).\n  - CVE-2023-0662: Fixed DoS vulnerability when parsing multipart request body (bnc#1208367).\n  - CVE-2023-0567: Fixed vulnerability where BCrypt hashes erroneously validate if the salt is cut short by `$` (bsc#1208388).\n","affected":[{"package":{"name":"php74","ecosystem":"SUSE:Linux Enterprise Module for Web and Scripting 12","purl":"pkg:rpm/suse/php74&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4.33-1.53.1"}]}],"ecosystem_specific":{"binaries":[{"apache2-mod_php74":"7.4.33-1.53.1","php74":"7.4.33-1.53.1","php74-bcmath":"7.4.33-1.53.1","php74-bz2":"7.4.33-1.53.1","php74-calendar":"7.4.33-1.53.1","php74-ctype":"7.4.33-1.53.1","php74-curl":"7.4.33-1.53.1","php74-dba":"7.4.33-1.53.1","php74-dom":"7.4.33-1.53.1","php74-enchant":"7.4.33-1.53.1","php74-exif":"7.4.33-1.53.1","php74-fastcgi":"7.4.33-1.53.1","php74-fileinfo":"7.4.33-1.53.1","php74-fpm":"7.4.33-1.53.1","php74-ftp":"7.4.33-1.53.1","php74-gd":"7.4.33-1.53.1","php74-gettext":"7.4.33-1.53.1","php74-gmp":"7.4.33-1.53.1","php74-iconv":"7.4.33-1.53.1","php74-intl":"7.4.33-1.53.1","php74-json":"7.4.33-1.53.1","php74-ldap":"7.4.33-1.53.1","php74-mbstring":"7.4.33-1.53.1","php74-mysql":"7.4.33-1.53.1","php74-odbc":"7.4.33-1.53.1","php74-opcache":"7.4.33-1.53.1","php74-openssl":"7.4.33-1.53.1","php74-pcntl":"7.4.33-1.53.1","php74-pdo":"7.4.33-1.53.1","php74-pgsql":"7.4.33-1.53.1","php74-phar":"7.4.33-1.53.1","php74-posix":"7.4.33-1.53.1","php74-readline":"7.4.33-1.53.1","php74-shmop":"7.4.33-1.53.1","php74-snmp":"7.4.33-1.53.1","php74-soap":"7.4.33-1.53.1","php74-sockets":"7.4.33-1.53.1","php74-sodium":"7.4.33-1.53.1","php74-sqlite":"7.4.33-1.53.1","php74-sysvmsg":"7.4.33-1.53.1","php74-sysvsem":"7.4.33-1.53.1","php74-sysvshm":"7.4.33-1.53.1","php74-tidy":"7.4.33-1.53.1","php74-tokenizer":"7.4.33-1.53.1","php74-xmlreader":"7.4.33-1.53.1","php74-xmlrpc":"7.4.33-1.53.1","php74-xmlwriter":"7.4.33-1.53.1","php74-xsl":"7.4.33-1.53.1","php74-zip":"7.4.33-1.53.1","php74-zlib":"7.4.33-1.53.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0515-1.json"}},{"package":{"name":"php74","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/php74&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4.33-1.53.1"}]}],"ecosystem_specific":{"binaries":[{"php74-devel":"7.4.33-1.53.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:0515-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20230515-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208366"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208367"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208388"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0567"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0568"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0662"}]}