Univention Bugzilla – Bug 53991
php7.0: Multiple issues (4.4)
Last modified: 2021-10-28 18:15:57 CEST
New Debian php7.0 7.0.33-0+deb9u12 fixes: This update addresses the following issue: * Local privilege escalation via PHP-FPM (CVE-2021-21703)
--- mirror/ftp/4.4/unmaintained/component/4.4-8-errata/source/php7.0_7.0.33-0+deb9u11.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/php7.0_7.0.33-0+deb9u12.dsc @@ -1,3 +1,14 @@ +7.0.33-0+deb9u12 [Tue, 26 Oct 2021 19:51:39 +0200] Sylvain Beucler <beuc@debian.org>: + + * Non-maintainer upload by the LTS Security Team. + * CVE-2021-21703: when running PHP FPM SAPI with main FPM daemon process + running as root and child worker processes running as lower-privileged + users, it is possible for the child processes to access memory shared + with the main process and write to it, modifying it in a way that + would cause the root process to conduct invalid memory reads and + writes, which can be used to escalate privileges from local + unprivileged user to the root user. + 7.0.33-0+deb9u11 [Mon, 12 Jul 2021 20:15:58 +0200] Sylvain Beucler <beuc@debian.org>: * Non-maintainer upload by the LTS Security Team. <http://piuparts.knut.univention.de/4.4-8/#28549591279822757>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] 42d998db6c Bug #53991: php7.0 7.0.33-0+deb9u12 doc/errata/staging/php7.0.yaml | 12 ++++++++++++ 1 file changed, 12 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1074>