Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-1444


Security update for php7


Type: security
Severity: moderate
Issued: 2024-04-26
Description:
This update for php7 fixes the following issues:

- CVE-2024-2756: Fixed bypass of security fix applied for CVE-2022-31629 that lead PHP to consider not secure cookies as secure (bsc#1222857)
- CVE-2024-3096: Fixed bypass on null byte leading passwords checked via password_verify (bsc#1222858)


              

Packages


  • php7-embed-7.4.33-150400.4.34.1