当前位置:网站首页>Cloud security daily 220705: the red hat PHP interpreter has found a vulnerability of executing arbitrary code, which needs to be upgraded as soon as possible
Cloud security daily 220705: the red hat PHP interpreter has found a vulnerability of executing arbitrary code, which needs to be upgraded as soon as possible
2022-07-05 17:17:00 【TechWeb】
7 month 4 Japan , Red hat has released a security update , Fixed red hat PHP Arbitrary code execution vulnerability found in the embedded scripting language interpreter . Here are the details of the vulnerability :
Vulnerability Details
source :https://access.redhat.com/errata/RHSA-2022:5491
1.CVE-2022-31625 CVSS score :8.1 severity : important
because pg_query_params() Uninitialized array in function , stay PHP A hole was found in . Use Postgres Database expansion , Providing invalid parameters for parameterized queries may result in PHP Try using uninitialized data as a pointer to free memory . This vulnerability allows remote attackers to control query parameters to execute arbitrary code on the system or may cause a denial of service .
2.CVE-2022-31626 CVSS score :7.5 severity : high
stay mysqlnd_wireprotocol.c In dealing with mysqlnd/pdo When the password in , stay PHP A buffer overflow vulnerability was found in . When using with mysqlnd Driver's pdo_mysql When expanding , If a third party is allowed to provide a password for the connecting host , An overly long password will trigger PHP Buffer overflow in . This vulnerability allows a remote attacker to pass through PDO Put the password ( Too long ) Pass to MySQL The server , This triggers arbitrary code execution on the target system .
3.CVE-2021-21703 CVSS score :6.4 severity : secondary
php-fpm There is a loophole , It may lead to local permission elevation . This vulnerability is difficult to exploit , Because the attack needs to escape FPM Sandbox mechanism . When a complete attack is achieved , May lead to confidentiality 、 Risks in data integrity and system availability .
4.CVE-2021-21707 CVSS score :5.3 severity : secondary
stay php.ini A flaw was found in . The main reason for this vulnerability is parsing extensible markup language (XML) The input validation of entity is incorrect . Special characters may allow attackers to traverse directories . The biggest threat of this vulnerability is confidentiality .
Affected products and versions
Red Hat Software Collections (for RHEL Server) 1 for RHEL 7 x86_64
Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7 s390x
Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7 ppc64le
Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7 x86_64
Solution
RedHat The official has Red Hat Software Collections Provide rh-php73-php Security update for . After installing the updated package , Must be restarted httpd The daemon can make the update take effect .
For more information on how to apply this update , see also :
https://access.redhat.com/articles/11258
View more vulnerability information And upgrade, please visit the official website :
https://access.redhat.com/security/security-updates/#/security-advisories
边栏推荐
- Etcd build a highly available etcd cluster
- 【jmeter】jmeter脚本高级写法:接口自动化脚本内全部为变量,参数(参数可jenkins配置),函数等实现完整业务流测试
- MySQL queries the latest qualified data rows
- It is forbidden to copy content JS code on the website page
- C#实现水晶报表绑定数据并实现打印3-二维码条形码
- 高数 | 旋转体体积计算方法汇总、二重积分计算旋转体体积
- Is it safe to open an account for digging wealth stocks? How is it safe to open a stock account?
- 叩富网开期货账户安全可靠吗?怎么分辨平台是否安全?
- [Jianzhi offer] 61 Shunzi in playing cards
- 微信公众号网页授权登录实现起来如此简单
猜你喜欢

Embedded -arm (bare board development) -1

PHP talent recruitment system development source code recruitment website source code secondary development
MySql 查询符合条件的最新数据行

33:第三章:开发通行证服务:16:使用Redis缓存用户信息;(以减轻数据库的压力)

Embedded UC (UNIX System Advanced Programming) -3

The two ways of domestic chip industry chain go hand in hand. ASML really panicked and increased cooperation on a large scale

CMake教程Step1(基本起点)

The first EMQ in China joined Amazon cloud technology's "startup acceleration - global partner network program"

Learnopongl notes (II) - Lighting

激动人心!2022开放原子全球开源峰会报名火热开启!
随机推荐
How does the outer disk futures platform distinguish formal security?
C language to get program running time
【剑指 Offer】63. 股票的最大利润
Embedded-c Language-4
[Jianzhi offer] 63 Maximum profit of stock
Judge whether a number is a prime number (prime number)
网上办理期货开户安全吗?网上会不会骗子比较多?感觉不太靠谱?
Learnopongl notes (II) - Lighting
Q2 encryption market investment and financing report in 2022: gamefi becomes an investment keyword
In depth understanding of redis memory obsolescence strategy
Writing method of twig array merging
WR | Jufeng group of West Lake University revealed the impact of microplastics pollution on the flora and denitrification function of constructed wetlands
How can C TCP set heartbeat packets to be elegant?
调查显示传统数据安全工具面对勒索软件攻击的失败率高达 60%
mysql如何使用JSON_EXTRACT()取json值
33: Chapter 3: develop pass service: 16: use redis to cache user information; (to reduce the pressure on the database)
The third lesson of EasyX learning
C# TCP如何限制单个客户端的访问流量
Embedded -arm (bare board development) -1
启牛商学院股票开户安全吗?靠谱吗?