<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2023-0215</id>
    <title>An update for php is now available for HCE 2.0</title>
    <severity>Important</severity>
    <release>HCE 2.0</release>
    <issued date="2023-06-28 16:11:19"/>
    <updated date="2023-06-28 16:11:19"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-0568" id="CVE-2023-0568" title="CVE-2023-0568 Base Score: 8.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-0662" id="CVE-2023-0662" title="CVE-2023-0662 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2022-31631" id="CVE-2022-31631" title="CVE-2022-31631 Base Score: 5.9 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-0567" id="CVE-2023-0567" title="CVE-2023-0567 Base Score: 6.2 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" type="cve"/>
    </references>
    <description>Security Fix(es):

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification. (CVE-2023-0568)

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space. (CVE-2023-0662)

The Oracle Linux Bulletin lists all CVEs that had been resolved and announced in Oracle Linux Security Advisories (ELSA) in the last one month prior to the release of the bulletin. Oracle Linux Bulletins are published on the same day as Oracle Critical Patch Updates are released. These bulletins will also be updated for the following two months after their release (i.e., the two months between the normal quarterly Critical Patch Update publication dates) to cover all CVEs that had been resolved in those two months following the bulletin's publication. In addition, Oracle Linux Bulletins may also be updated for vulnerability issues deemed too critical to wait for the next scheduled bulletin publication date. (CVE-2022-31631)

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid. (CVE-2023-0567)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="php">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="php" version="8.0.28" release="1.hce2">
          <filename>php-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-bcmath" version="8.0.28" release="1.hce2">
          <filename>php-bcmath-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-cli" version="8.0.28" release="1.hce2">
          <filename>php-cli-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-common" version="8.0.28" release="1.hce2">
          <filename>php-common-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-dba" version="8.0.28" release="1.hce2">
          <filename>php-dba-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-dbg" version="8.0.28" release="1.hce2">
          <filename>php-dbg-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-devel" version="8.0.28" release="1.hce2">
          <filename>php-devel-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-embedded" version="8.0.28" release="1.hce2">
          <filename>php-embedded-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-enchant" version="8.0.28" release="1.hce2">
          <filename>php-enchant-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-ffi" version="8.0.28" release="1.hce2">
          <filename>php-ffi-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-fpm" version="8.0.28" release="1.hce2">
          <filename>php-fpm-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-gd" version="8.0.28" release="1.hce2">
          <filename>php-gd-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-gmp" version="8.0.28" release="1.hce2">
          <filename>php-gmp-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-help" version="8.0.28" release="1.hce2">
          <filename>php-help-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-intl" version="8.0.28" release="1.hce2">
          <filename>php-intl-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-ldap" version="8.0.28" release="1.hce2">
          <filename>php-ldap-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-mbstring" version="8.0.28" release="1.hce2">
          <filename>php-mbstring-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-mysqlnd" version="8.0.28" release="1.hce2">
          <filename>php-mysqlnd-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-odbc" version="8.0.28" release="1.hce2">
          <filename>php-odbc-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-opcache" version="8.0.28" release="1.hce2">
          <filename>php-opcache-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-pdo" version="8.0.28" release="1.hce2">
          <filename>php-pdo-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-pgsql" version="8.0.28" release="1.hce2">
          <filename>php-pgsql-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-process" version="8.0.28" release="1.hce2">
          <filename>php-process-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-snmp" version="8.0.28" release="1.hce2">
          <filename>php-snmp-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-soap" version="8.0.28" release="1.hce2">
          <filename>php-soap-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-tidy" version="8.0.28" release="1.hce2">
          <filename>php-tidy-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="php-xml" version="8.0.28" release="1.hce2">
          <filename>php-xml-8.0.28-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="php" version="8.0.28" release="1.hce2">
          <filename>php-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-bcmath" version="8.0.28" release="1.hce2">
          <filename>php-bcmath-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-cli" version="8.0.28" release="1.hce2">
          <filename>php-cli-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-common" version="8.0.28" release="1.hce2">
          <filename>php-common-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-dba" version="8.0.28" release="1.hce2">
          <filename>php-dba-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-dbg" version="8.0.28" release="1.hce2">
          <filename>php-dbg-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-devel" version="8.0.28" release="1.hce2">
          <filename>php-devel-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-embedded" version="8.0.28" release="1.hce2">
          <filename>php-embedded-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-enchant" version="8.0.28" release="1.hce2">
          <filename>php-enchant-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-ffi" version="8.0.28" release="1.hce2">
          <filename>php-ffi-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-fpm" version="8.0.28" release="1.hce2">
          <filename>php-fpm-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-gd" version="8.0.28" release="1.hce2">
          <filename>php-gd-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-gmp" version="8.0.28" release="1.hce2">
          <filename>php-gmp-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-help" version="8.0.28" release="1.hce2">
          <filename>php-help-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-intl" version="8.0.28" release="1.hce2">
          <filename>php-intl-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-ldap" version="8.0.28" release="1.hce2">
          <filename>php-ldap-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-mbstring" version="8.0.28" release="1.hce2">
          <filename>php-mbstring-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-mysqlnd" version="8.0.28" release="1.hce2">
          <filename>php-mysqlnd-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-odbc" version="8.0.28" release="1.hce2">
          <filename>php-odbc-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-opcache" version="8.0.28" release="1.hce2">
          <filename>php-opcache-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-pdo" version="8.0.28" release="1.hce2">
          <filename>php-pdo-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-pgsql" version="8.0.28" release="1.hce2">
          <filename>php-pgsql-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-process" version="8.0.28" release="1.hce2">
          <filename>php-process-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-snmp" version="8.0.28" release="1.hce2">
          <filename>php-snmp-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-soap" version="8.0.28" release="1.hce2">
          <filename>php-soap-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-tidy" version="8.0.28" release="1.hce2">
          <filename>php-tidy-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="php-xml" version="8.0.28" release="1.hce2">
          <filename>php-xml-8.0.28-1.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
