Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2022-2292


Security update for php7


Type: security
Severity: important
Issued: 2022-07-06
Description:
This update for php7 fixes the following issues:

- CVE-2021-21707: Fixed a special character breaks path in xml parsing. (bsc#1193041)
- CVE-2022-31625: Fixed uninitialized pointers free in Postgres extension. (bsc#1200645)
- CVE-2022-31626: Fixed buffer overflow via user-supplied password when using pdo_mysql extension with mysqlnd driver. (bsc#1200628)


              

Packages


  • php7-embed-7.4.25-150400.4.8.1