Debian dsa-5661 : libapache2-mod-php8.2 - security update

critical Nessus Plugin ID 193346

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 12 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-5661 advisory.

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512

- ------------------------------------------------------------------------- Debian Security Advisory DSA-5661-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff April 15, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : php8.2 CVE ID : CVE-2023-3823 CVE-2023-3824 CVE-2024-2756 CVE-2024-3096

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in secure cookie bypass, XXE attacks or incorrect validation of password hashes.

For the stable distribution (bookworm), these problems have been fixed in version 8.2.18-1~deb12u1.

We recommend that you upgrade your php8.2 packages.

For the detailed security status of php8.2 please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/php8.2

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmYdfYMACgkQEMKTtsN8 TjbrZxAAotqJ1fIulmY7fP/Ll2Gb/aoswnUqZTNiZH/yrzwX86cggI61EaWXc/JW 7O5i7+U4y63ZIl5M6HVFk5bNgnj6Rwl5bT+jz8dbqLKkphIkT0754h1bdXCaW73r iiNztNclAITPYMOntY7TEWZuqS2p4cNjUuHYoPiqCLU8ASMoi/z2DHFWBc6uBLRR RqbhbdFbWeekzc6nt+JZmEVD9JLXsh8kO4/f5o1pbCx6pYerWM1Win5AW6ZBSNMd 5xO5DTP3F/RX7BEyH7rTQ0y2TRCY4qk2LKG4cojqidgHIpCiTiFiKvk9W3EJZdKe brzHyBgEixzCImvYze68j0M0ruxWiTTozKEn9Tj7DSPNoD+vB6U8kGAqmG3b5q+p w9BSCQ+AZ25HvDqdasH8gaj8Ji4xAhWxVutQRrSbhcf3xKu8Y6taz3ANIRXBmgjE ARhK9p4b66KauAxG5GavWQQQprcbzt0deGUK6WkxigQ04l38kIrD9XIXnMHBEH4/ Aas8E6zv8+j+18RdPaSGDGTAvuJD/C9GQjWfIvRXYVjUKarlWgtrgDoxGIMlOIHh RwgyJdZzJAx2vAY2o1CYmtIS59zReqwK+rAtogFi2RIoruVPGLccgxcqJOtvJF7M XGBAVp+3Wi4SFK5QHu1ISlngw+LkNJdkz1yXcUVI6vLt0QQEt94= =xxUv
-----END PGP SIGNATURE-----

Reply to:
[email protected] Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list)

Prev by Date:
[SECURITY] [DSA 5660-1] php7.4 security update

Next by Date:
[SECURITY] [DSA 5662-1] apache2 security update

Previous by thread:
[SECURITY] [DSA 5660-1] php7.4 security update

Next by thread:
[SECURITY] [DSA 5662-1] apache2 security update

Index(es):

Date Thread

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the libapache2-mod-php8.2 packages.

See Also

https://security-tracker.debian.org/tracker/source-package/php8.2

https://security-tracker.debian.org/tracker/CVE-2023-3823

https://security-tracker.debian.org/tracker/CVE-2023-3824

https://security-tracker.debian.org/tracker/CVE-2024-2756

https://security-tracker.debian.org/tracker/CVE-2024-3096

https://packages.debian.org/source/bookworm/php8.2

Plugin Details

Severity: Critical

ID: 193346

File Name: debian_DSA-5661.nasl

Version: 1.3

Type: local

Agent: unix

Published: 4/16/2024

Updated: 1/24/2025

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-3824

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:php8.2-cgi, p-cpe:/a:debian:debian_linux:php8.2-phpdbg, p-cpe:/a:debian:debian_linux:php8.2-enchant, p-cpe:/a:debian:debian_linux:php8.2-sqlite3, p-cpe:/a:debian:debian_linux:php8.2-tidy, p-cpe:/a:debian:debian_linux:php8.2-curl, cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:php8.2-common, p-cpe:/a:debian:debian_linux:php8.2-readline, p-cpe:/a:debian:debian_linux:php8.2-pgsql, p-cpe:/a:debian:debian_linux:php8.2-bz2, p-cpe:/a:debian:debian_linux:libphp8.2-embed, p-cpe:/a:debian:debian_linux:php8.2-mbstring, p-cpe:/a:debian:debian_linux:php8.2-sybase, p-cpe:/a:debian:debian_linux:php8.2-xml, p-cpe:/a:debian:debian_linux:php8.2-pspell, p-cpe:/a:debian:debian_linux:php8.2-soap, p-cpe:/a:debian:debian_linux:php8.2-snmp, p-cpe:/a:debian:debian_linux:php8.2-dev, p-cpe:/a:debian:debian_linux:php8.2-gmp, p-cpe:/a:debian:debian_linux:php8.2-dba, p-cpe:/a:debian:debian_linux:php8.2-ldap, p-cpe:/a:debian:debian_linux:php8.2-mysql, p-cpe:/a:debian:debian_linux:php8.2-fpm, p-cpe:/a:debian:debian_linux:libapache2-mod-php8.2, p-cpe:/a:debian:debian_linux:php8.2-intl, p-cpe:/a:debian:debian_linux:php8.2, p-cpe:/a:debian:debian_linux:php8.2-gd, p-cpe:/a:debian:debian_linux:php8.2-interbase, p-cpe:/a:debian:debian_linux:php8.2-bcmath, p-cpe:/a:debian:debian_linux:php8.2-xsl, p-cpe:/a:debian:debian_linux:php8.2-zip, p-cpe:/a:debian:debian_linux:php8.2-cli, p-cpe:/a:debian:debian_linux:php8.2-odbc, p-cpe:/a:debian:debian_linux:php8.2-imap, p-cpe:/a:debian:debian_linux:php8.2-opcache

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/15/2024

Vulnerability Publication Date: 8/3/2023

Reference Information

CVE: CVE-2023-3823, CVE-2023-3824, CVE-2024-2756, CVE-2024-3096

IAVA: 2024-A-0244-S