Charles Fol discovered two security issues in PHP, a widely-used open
source general purpose scripting language which could result an denial of
service or potentially the execution of arbitrary code:
Category Archives: Advisories
USN-5479-3: PHP regression
USN-5479-1 fixed vulnerabilities in PHP. Unfortunately that update for
CVE-2022-31625 was incomplete for Ubuntu 18.04 LTS. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
Charles Fol discovered that PHP incorrectly handled initializing certain
arrays when handling the pg_query_params function. A remote attacker could
use this issue to cause PHP to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2022-31625)
Charles Fol discovered that PHP incorrectly handled passwords in mysqlnd. A
remote attacker could use this issue to cause PHP to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2022-31626)
kernel-5.18.10-200.fc36
FEDORA-2022-d280d3b05d
Packages in this update:
kernel-5.18.10-200.fc36
Update description:
The 5.18.10 stable kernel update contains a number of important fixes across the tree.
kernel-5.18.10-100.fc35
FEDORA-2022-b47003a52b
Packages in this update:
kernel-5.18.10-100.fc35
Update description:
The 5.18.10 stable kernel update contains a number of important fixes across the tree.
grafana-9.0.2-1.fc37
FEDORA-2022-94a5e6bf82
Packages in this update:
grafana-9.0.2-1.fc37
Update description:
Automatic update for grafana-9.0.2-1.fc37.
Changelog
* Thu Jul 7 2022 Andreas Gerstmayr <agerstmayr@redhat.com> 9.0.2-1
– update to 9.0.2 tagged upstream community sources, see CHANGELOG
CVE-2014-3644
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
CVE-2014-3658
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
CVE-2014-3705
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
CVE-2014-3918
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
CVE-2014-0024
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.