Nous utilisons des cookies pour améliorer notre page Web. Veuillez lire notre politique relative aux cookies .

AS-2023-008: PHP 8.1

2023-06-07

Severity

Important

Status

Resolved


Statement

The PHP Group announced multiple vulnerabilities that have been fixed in the latest release of PHP 8.1.

CVE-2023-0662, CVE-2022-31631, CVE-2022-31630, CVE-2022-37454, CVE-2022-31628, CVE-2022-31629 and CVE-2022-31627 will affect ASUSTOR products with PHP 8.1 installed on ADM 4.1 or ADM 4.2

  • Updates with PHP 8.1.18 has been released on App Central for ADM 4.2.2.

Affected Products

Product Severity Fixed Release Availability
ADM 4.2 and 4.1 Important Upgrade PHP 8.1 to 8.1.18.r21 or above.

Detail

  • CVE-2023-0662
    • Severity: High
    • In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.
  • CVE-2022-31630
    • Severity: High
    • In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.
  • CVE-2022-31629
    • Severity: Medium
    • In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.
  • CVE-2022-31628
    • Severity: Medium
    • In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
  • CVE-2022-31627
    • Severity: Critical
    • In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

Reference


Revision

Revision Date Description
1 2023-06-05 Initial public release.
2 2023-06-07 Update PHP 8.1 to 8.1.18.r21 for fixing the issues on ADM 4.2.2.