QID 198429
Date Published: 2021-07-12
QID 198429: Ubuntu Security Notification for Hypertext Preprocessor vulnerabilities (USN-5006-1)
Php incorrectly handled certain phar files.
Php incorrectly handled parsing urls with passwords.
Php incorrectly handled certain malformed xml data when being parsed by the soap extension.
Php incorrectly handled the pdo_firebase module.
Php incorrectly handled the filter_validate_url check.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
a remote attacker could possibly use this issue to cause php to crash, resulting in a denial of service, or possibly obtain sensitive information.
This issue only affected ubuntu 18.04 lts and ubuntu 20.04 lts. (
Cve-2020-7068).
a remote attacker could possibly use this issue to cause php to mis-parse the url and produce wrong data.
This issue only affected ubuntu 18.04 lts, ubuntu 20.04 lts, and ubuntu 20.10. (
Cve-2020-7071).
A remote attacker could possibly use this issue to cause php to crash, resulting in a denial of service.
this issue only affected ubuntu 18.04 lts, ubuntu 20.04 lts, and ubuntu 20.10. (
Cve-2021-21702).
A remote attacker could possibly use this issue to cause php to crash, resulting in a denial of service. (
Cve-2021-21704).
A remote attacker could possibly use this issue to perform a server- side request forgery attack. (
Cve-2021-21705).
- USN-5006-1 -
usn.ubuntu.com/5006-1
CVEs related to QID 198429
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-5006-1 | Ubuntu Linux |
|