- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202408-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: PHP: Multiple Vulnerabilities Date: August 12, 2024 Bugs: #889882, #895416, #908259, #912331, #929929, #933752 ID: 202408-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in PHP, the worst of which can lead to a denial of service. Background ========= PHP is a widely-used general-purpose scripting language that is especially suited for Web development and can be embedded into HTML. Affected packages ================ Package Vulnerable Unaffected ------------ ------------- ------------- dev-lang/php >= 8.1.29:8.1 >= 8.1.29:8.1 >= 8.2.20:8.2 >= 8.2.20:8.2 >= 8.3.8:8.3 >= 8.3.8:8.3 < 8.1 >= 8.1.29 Description ========== Multiple vulnerabilities have been discovered in PHP. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All PHP users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">Þv-lang/php-8.1.29:8.1" # emerge --ask --oneshot --verbose ">Þv-lang/php-8.2.20:8.2" # emerge --ask --oneshot --verbose ">Þv-lang/php-8.3.8:8.3" Support for older version has been discontinued: # emerge --ask --verbose --depclean "