Alpine: multiple php83 packages: security update to 8.3.6-r0

critical Tenable Self-Hosted Container Security Plugin ID 408366

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open()
command with array syntax, due to insufficient escaping, if the arguments of the executed command are
controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in
Windows shell. (CVE-2024-1874)

- Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and
same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a
__Host- or __Secure- cookie by PHP applications. (CVE-2024-2756)

- In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain
long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a
hostile user sends data to an application that uses this function. (CVE-2024-2757)

- In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with
password_hash() starts with a null byte (\x00), testing a blank string as the password via
password_verify() will incorrectly return true. (CVE-2024-3096)

See Also

https://security.alpinelinux.org/vuln/CVE-2024-1874

https://security.alpinelinux.org/vuln/CVE-2024-2756

https://security.alpinelinux.org/vuln/CVE-2024-2757

https://security.alpinelinux.org/vuln/CVE-2024-3096

Plugin Details

Severity: Critical

ID: 408366

Version: Revision 1.10

Type: Local

Published: 4/11/2024

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.5

Percentile: 57.4

CVSS v2

Risk Factor: High

Base Score: 9.7

Temporal Score: 7.6

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:P

CVSS Score Source: CVE-2024-1874

CVSS v3

Risk Factor: Critical

Base Score: 9.4

Temporal Score: 8.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 4/10/2024

Reference Information

CVE: CVE-2024-1874, CVE-2024-2756, CVE-2024-2757, CVE-2024-3096

IAVA: 2024-A-0244-S