Bug 1192050 (CVE-2021-21703) - VUL-0: CVE-2021-21703: php74,php5,php72,php53,php7: php: Local privilege escalation via PHP-FPM
Summary: VUL-0: CVE-2021-21703: php74,php5,php72,php53,php7: php: Local privilege esca...
Status: RESOLVED FIXED
Alias: CVE-2021-21703
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/313401/
Whiteboard: CVSSv3.1:SUSE:CVE-2021-21703:6.4:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2021-10-26 14:39 UTC by Gabriele Sonnu
Modified: 2024-07-19 12:45 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Gabriele Sonnu 2021-10-26 14:43:19 UTC
Affected packages:

 - SUSE:SLE-11-SP3:Update/php53  5.3.17
 - SUSE:SLE-12:Update/php5       5.5.14
 - SUSE:SLE-12:Update/php7        7.0.7
 - SUSE:SLE-12:Update/php72       7.2.5
 - SUSE:SLE-12:Update/php74       7.4.6
 - SUSE:SLE-15-SP2:Update/php7    7.4.6
 - SUSE:SLE-15:Update/php7        7.2.5
 - openSUSE:Factory/php7         7.4.24

Upstream patch:
https://github.com/php/php-src/commit/cb2021e5f69da5e2868130a05bb53db0f9f89e4b
Comment 2 Petr Gajdos 2021-10-27 13:23:54 UTC
(In reply to Gabriele Sonnu from comment #1)
>  - openSUSE:Factory/php7         7.4.24
This is already fixed: 7.4.25 is in Factory yet.
Also 7.4.25 have been submitted into SUSE:SLE-15-SP4:GA.
https://build.suse.de/request/show/257194
Comment 3 Petr Gajdos 2021-10-27 13:30:59 UTC
(In reply to Gabriele Sonnu from comment #1)
>  - SUSE:SLE-11-SP3:Update/php53  5.3.17

https://maintenance.suse.de/maintained/ for php53 does not show php53-fpm, so I think it is not supported.

>  - SUSE:SLE-12:Update/php5       5.5.14
>  - SUSE:SLE-12:Update/php7        7.0.7

As far as I know from
https://confluence.suse.com/display/SLE/PHP
these codestreams are not supported anymore.

Please correct me if I am wrong.
Comment 4 Petr Gajdos 2021-10-29 10:25:03 UTC
Packages submitted in 15sp2,15/php7, 12/php74 and 12/php72.
Comment 6 Swamp Workflow Management 2021-11-18 17:17:46 UTC
SUSE-SU-2021:3726-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1192050
CVE References: CVE-2021-21703
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    php74-7.4.6-1.27.1
SUSE Linux Enterprise Module for Web Scripting 12 (src):    php74-7.4.6-1.27.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2021-11-19 14:17:53 UTC
SUSE-SU-2021:3727-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1192050
CVE References: CVE-2021-21703
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    php72-7.2.5-1.72.1
SUSE Linux Enterprise Module for Web Scripting 12 (src):    php72-7.2.5-1.72.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2021-12-06 17:18:47 UTC
SUSE-SU-2021:3943-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1175508,1192050,1193041
CVE References: CVE-2021-21703,CVE-2021-21707
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Web Scripting 15-SP3 (src):    php7-7.4.6-3.29.1
SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src):    php7-7.4.6-3.29.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    php7-7.4.6-3.29.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 (src):    php7-7.4.6-3.29.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2021-12-06 17:31:11 UTC
openSUSE-SU-2021:3943-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1175508,1192050,1193041
CVE References: CVE-2021-21703,CVE-2021-21707
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    php7-7.4.6-3.29.1, php7-test-7.4.6-3.29.1
Comment 11 Swamp Workflow Management 2021-12-10 20:22:59 UTC
openSUSE-SU-2021:1570-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1175508,1192050,1193041
CVE References: CVE-2021-21703,CVE-2021-21707
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    php7-7.4.6-lp152.2.21.1, php7-test-7.4.6-lp152.2.21.1
Comment 14 Swamp Workflow Management 2022-03-02 23:19:48 UTC
openSUSE-SU-2022:0679-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1038980,1081790,1192050,1193041
CVE References: CVE-2015-9253,CVE-2017-8923,CVE-2021-21703,CVE-2021-21707
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    php7-7.2.5-4.89.4
Comment 15 Swamp Workflow Management 2022-03-02 23:20:47 UTC
SUSE-SU-2022:0679-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1038980,1081790,1192050,1193041
CVE References: CVE-2015-9253,CVE-2017-8923,CVE-2021-21703,CVE-2021-21707
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    php7-7.2.5-4.89.4
SUSE Linux Enterprise Server for SAP 15 (src):    php7-7.2.5-4.89.4
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    php7-7.2.5-4.89.4
SUSE Linux Enterprise Server 15-SP1-BCL (src):    php7-7.2.5-4.89.4
SUSE Linux Enterprise Server 15-LTSS (src):    php7-7.2.5-4.89.4
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    php7-7.2.5-4.89.4
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    php7-7.2.5-4.89.4
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    php7-7.2.5-4.89.4
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    php7-7.2.5-4.89.4
SUSE Enterprise Storage 6 (src):    php7-7.2.5-4.89.4
SUSE CaaS Platform 4.0 (src):    php7-7.2.5-4.89.4

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Swamp Workflow Management 2022-10-19 16:22:28 UTC
SUSE-SU-2022:3661-1: An update that solves three vulnerabilities, contains two features and has one errata is now available.

Category: security (important)
Bug References: 1192050,1200772,1203867,1203870
CVE References: CVE-2021-21703,CVE-2022-31628,CVE-2022-31629
JIRA References: SLE-23639,SLE-24723
Sources used:
openSUSE Leap 15.4 (src):    apache2-mod_php8-8.0.24-150400.4.14.1, php8-8.0.24-150400.4.14.1, php8-embed-8.0.24-150400.4.14.1, php8-fastcgi-8.0.24-150400.4.14.1, php8-fpm-8.0.24-150400.4.14.1, php8-test-8.0.24-150400.4.14.1
SUSE Linux Enterprise Module for Web Scripting 15-SP4 (src):    apache2-mod_php8-8.0.24-150400.4.14.1, php8-8.0.24-150400.4.14.1, php8-embed-8.0.24-150400.4.14.1, php8-fastcgi-8.0.24-150400.4.14.1, php8-fpm-8.0.24-150400.4.14.1, php8-test-8.0.24-150400.4.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 OBSbugzilla Bot 2023-09-26 10:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1192050) was mentioned in
https://build.opensuse.org/request/show/1113638 Factory / php8
Comment 18 Andrea Mattiazzo 2024-07-19 12:45:27 UTC
All done, closing.