Lucene search

K
suseSuseSUSE-SU-2022:3020-1
HistorySep 05, 2022 - 12:00 a.m.

Security update for php-composer2 (important)

2022-09-0500:00:00
lists.opensuse.org
19
php composer2 vulnerability patch
code injection issue fix
suse security update

EPSS

0.003

Percentile

65.3%

An update that fixes one vulnerability is now available.

Description:

This update for php-composer2 fixes the following issues:

  • CVE-2022-24828: Fixed a code injection issue that affected integrators
    using specific APIs to read untrusted input files (bsc#1198494).

Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.4:

    zypper in -t patch openSUSE-SLE-15.4-2022-3020=1

  • SUSE Linux Enterprise Module for Web Scripting 15-SP4:

    zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP4-2022-3020=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.4noarch< - openSUSE Leap 15.4 (noarch):- openSUSE Leap 15.4 (noarch):.noarch.rpm
SUSE Linux Enterprise Module for Web Scripting 15SP4noarch<  SUSE Linux Enterprise Module for Web Scripting 15-SP4 (noarch):- SUSE Linux Enterprise Module for Web Scripting 15-SP4 (noarch):.noarch.rpm