UbuntuUpdates.org

Package "php8.2"

Name: php8.2

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • HTML-embedded scripting language (Embedded SAPI library)
  • Bcmath module for PHP
  • bzip2 module for PHP
  • DBA module for PHP

Latest version: 8.2.10-2ubuntu2.1
Release: mantic (23.10)
Level: updates
Repository: universe

Links



Other versions of "php8.2" in Mantic

Repository Area Version
base main 8.2.10-2ubuntu1
security main 8.2.10-2ubuntu2.1
security universe 8.2.10-2ubuntu2.1
updates main 8.2.10-2ubuntu2.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 8.2.10-2ubuntu2.1 2024-05-03 04:07:05 UTC

  php8.2 (8.2.10-2ubuntu2.1) mantic-security; urgency=medium

  * SECURITY UPDATE: Cookie by pass
    - debian/patches/CVE-2024-2756.patch: adds more mangling rules
      in main/php_variable.c.
    - CVE-2024-2756
  * SECURITY UPDATE: Account take over risk
    - debian/patches/CVE-2024-3096.patch: disallow null character in bcrypt
      password in ext/standard/password.c,
      ext/standard/tests/password_bcrypt_errors.phpt.
    - CVE-2024-3096

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 01 May 2024 07:15:40 -0300

CVE-2024-2756 Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard in
CVE-2024-3096 In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00



About   -   Send Feedback to @ubuntu_updates