AIX Open Source

AIX Open Source

Share your experiences and connect with fellow developers to discover how to build and manage open source software for the AIX operating system

 View Only
  • 1.  PHP Version 7.4.28 or newer

    Posted Mon March 07, 2022 07:30 AM
    Hi there

    Is there an estimate when we can expect PHP 7.4.28 or newer to adress the following Vulnerability CVE-2021-21708 ?

    Thanks in advance and kind regards

    Stefano

    ------------------------------
    Stefano Calisto
    ------------------------------


  • 2.  RE: PHP Version 7.4.28 or newer

    Posted Fri March 11, 2022 12:17 PM
    Edited by SANKET RATHI Fri March 11, 2022 12:19 PM
    Hi Stefano,

    The CVE is published recently and we will work on getting the fixed version of PHP from community and build and test on AIX.
    There are some internal process also involved. 
    We have other packages those needs to be published for security fixes we will try to prioritise it. 

    ------------------------------
    SANKET RATHI
    ------------------------------



  • 3.  RE: PHP Version 7.4.28 or newer

    Posted Mon March 14, 2022 06:22 AM
    Thanks in advance. I appreciate the effort very much !!

    Kind regards,

    Stefano

    ------------------------------
    Stefano Calisto
    ------------------------------



  • 4.  RE: PHP Version 7.4.28 or newer

    Posted Tue November 15, 2022 08:17 AM
    Hi Sanket


    Is there an estimate when we can expect PHP 7.4.34  to address the following Vulnerability CVE-2022-2224[1-6] and CVE-2022-31630, CVE-2022-37454?

    Thanks in advance and best regards,
    Michel

    ------------------------------
    Michel Gehring
    ------------------------------



  • 5.  RE: PHP Version 7.4.28 or newer

    Posted Wed November 16, 2022 09:30 AM
    We will update it as soon as possible.

    ------------------------------
    Ayappan P
    ------------------------------



  • 6.  RE: PHP Version 7.4.28 or newer

    Posted Fri December 02, 2022 12:24 AM

    We have published php 7.4.33 in AIX Toolbox. This version has fix for CVE-2022-31630 and CVE-2022-37454.
    https://public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/RPMS/ppc/php/
    CVE-2022-2224[1-6]  seems to be affecting Juniper Networks Junos OS, not php.



    ------------------------------
    RESHMA KUMAR
    ------------------------------



  • 7.  RE: PHP Version 7.4.28 or newer

    Posted Fri December 02, 2022 01:32 AM

    Great. Many thanks!