CentOS 8 : php:7.4 (CESA-2022:7628)
Discription
The remote CentOS Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the CESA-2022:7628 advisory.
– php: Special character breaks path in xml parsing (CVE-2021-21707)
– php: Use after free due to php_filter_float() failing for ints (CVE-2021-21708)
– php-pear: Directory traversal vulnerability (CVE-2021-32610)
Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.Read More
References
Back to Main