[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-384 --- composer

ID: oval:org.secpod.oval:def:19500457Date: (C)2024-01-04   (M)2024-04-03
Class: PATCHFamily: unix




Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has 'register_argc_argv' enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure 'register_argc_argv' is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice

Platform:
Amazon Linux 2023
Product:
composer
Reference:
ALAS2023-2023-384
CVE-2023-43655
CVE    1
CVE-2023-43655
CPE    1
cpe:/a:getcomposer:composer

© SecPod Technologies