Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP2-2020-2941


Security update for php7


Type: security
Severity: important
Issued: 2020-10-16
Description:
This update for php7 fixes the following issues:

- CVE-2020-7069: Fixed an issue when AES-CCM mode was used with openssl_encrypt() function with 12 bytes IV, 
  only first 7 bytes of the IV was used (bsc#1177351). 
- CVE-2020-7070: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1177352).


              

Packages


  • php7-7.4.6-3.11.1