Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 6 |
CVE-ID | CVE-2024-11235 CVE-2025-1217 CVE-2025-1219 CVE-2025-1734 CVE-2025-1736 CVE-2025-1861 |
CWE-ID | CWE-416 CWE-20 CWE-399 CWE-287 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
SUSE Linux Enterprise High Performance Computing LTSS 15 Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing ESPOS 15 Operating systems & Components / Operating system SUSE Linux Enterprise Server 15 SP5 Operating systems & Components / Operating system SUSE Linux Enterprise Server 15 SP4 Operating systems & Components / Operating system SUSE Linux Enterprise Server for SAP Applications 15 Operating systems & Components / Operating system SUSE Linux Enterprise Server 15 Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing 15 Operating systems & Components / Operating system SUSE Manager Server Operating systems & Components / Operating system openSUSE Leap Operating systems & Components / Operating system php8-phar Operating systems & Components / Operating system package or component php8-shmop Operating systems & Components / Operating system package or component php8-gd Operating systems & Components / Operating system package or component php8-pdo Operating systems & Components / Operating system package or component php8-embed-debugsource Operating systems & Components / Operating system package or component php8-embed Operating systems & Components / Operating system package or component php8-fpm Operating systems & Components / Operating system package or component php8-sockets Operating systems & Components / Operating system package or component php8-sodium-debuginfo Operating systems & Components / Operating system package or component php8-odbc Operating systems & Components / Operating system package or component php8-fpm-debugsource Operating systems & Components / Operating system package or component php8-tokenizer-debuginfo Operating systems & Components / Operating system package or component php8-zlib Operating systems & Components / Operating system package or component php8-dom-debuginfo Operating systems & Components / Operating system package or component apache2-mod_php8-debugsource Operating systems & Components / Operating system package or component php8-gettext Operating systems & Components / Operating system package or component php8-sysvsem-debuginfo Operating systems & Components / Operating system package or component php8-dba Operating systems & Components / Operating system package or component php8-bz2-debuginfo Operating systems & Components / Operating system package or component php8-curl Operating systems & Components / Operating system package or component php8-xmlreader-debuginfo Operating systems & Components / Operating system package or component php8-odbc-debuginfo Operating systems & Components / Operating system package or component php8-fastcgi Operating systems & Components / Operating system package or component php8-sysvsem Operating systems & Components / Operating system package or component php8-cli Operating systems & Components / Operating system package or component php8-dom Operating systems & Components / Operating system package or component php8-gettext-debuginfo Operating systems & Components / Operating system package or component php8-tidy-debuginfo Operating systems & Components / Operating system package or component php8-pgsql Operating systems & Components / Operating system package or component php8-bcmath Operating systems & Components / Operating system package or component php8-posix Operating systems & Components / Operating system package or component php8-dba-debuginfo Operating systems & Components / Operating system package or component php8-bz2 Operating systems & Components / Operating system package or component php8-shmop-debuginfo Operating systems & Components / Operating system package or component php8-gd-debuginfo Operating systems & Components / Operating system package or component php8-xsl-debuginfo Operating systems & Components / Operating system package or component php8-sockets-debuginfo Operating systems & Components / Operating system package or component php8-calendar Operating systems & Components / Operating system package or component php8-embed-debuginfo Operating systems & Components / Operating system package or component php8-fileinfo-debuginfo Operating systems & Components / Operating system package or component php8-zlib-debuginfo Operating systems & Components / Operating system package or component php8-sodium Operating systems & Components / Operating system package or component php8-intl Operating systems & Components / Operating system package or component php8-mbstring Operating systems & Components / Operating system package or component apache2-mod_php8-debuginfo Operating systems & Components / Operating system package or component php8-ftp-debuginfo Operating systems & Components / Operating system package or component php8-gmp-debuginfo Operating systems & Components / Operating system package or component php8-debuginfo Operating systems & Components / Operating system package or component php8-pcntl Operating systems & Components / Operating system package or component php8-sysvshm Operating systems & Components / Operating system package or component php8-mbstring-debuginfo Operating systems & Components / Operating system package or component php8-ctype-debuginfo Operating systems & Components / Operating system package or component php8-bcmath-debuginfo Operating systems & Components / Operating system package or component php8-devel Operating systems & Components / Operating system package or component php8-tidy Operating systems & Components / Operating system package or component php8-soap Operating systems & Components / Operating system package or component php8 Operating systems & Components / Operating system package or component php8-zip-debuginfo Operating systems & Components / Operating system package or component php8-exif-debuginfo Operating systems & Components / Operating system package or component php8-curl-debuginfo Operating systems & Components / Operating system package or component php8-opcache Operating systems & Components / Operating system package or component php8-mysql Operating systems & Components / Operating system package or component php8-test Operating systems & Components / Operating system package or component php8-iconv Operating systems & Components / Operating system package or component php8-readline Operating systems & Components / Operating system package or component php8-ftp Operating systems & Components / Operating system package or component php8-posix-debuginfo Operating systems & Components / Operating system package or component php8-intl-debuginfo Operating systems & Components / Operating system package or component php8-sqlite Operating systems & Components / Operating system package or component php8-iconv-debuginfo Operating systems & Components / Operating system package or component php8-debugsource Operating systems & Components / Operating system package or component php8-xmlreader Operating systems & Components / Operating system package or component php8-xmlwriter-debuginfo Operating systems & Components / Operating system package or component php8-xmlwriter Operating systems & Components / Operating system package or component php8-calendar-debuginfo Operating systems & Components / Operating system package or component php8-snmp-debuginfo Operating systems & Components / Operating system package or component php8-opcache-debuginfo Operating systems & Components / Operating system package or component php8-zip Operating systems & Components / Operating system package or component php8-ldap Operating systems & Components / Operating system package or component php8-cli-debuginfo Operating systems & Components / Operating system package or component php8-pcntl-debuginfo Operating systems & Components / Operating system package or component php8-gmp Operating systems & Components / Operating system package or component php8-sysvmsg Operating systems & Components / Operating system package or component php8-enchant Operating systems & Components / Operating system package or component apache2-mod_php8 Operating systems & Components / Operating system package or component php8-phar-debuginfo Operating systems & Components / Operating system package or component php8-sysvshm-debuginfo Operating systems & Components / Operating system package or component php8-exif Operating systems & Components / Operating system package or component php8-sysvmsg-debuginfo Operating systems & Components / Operating system package or component php8-fastcgi-debuginfo Operating systems & Components / Operating system package or component php8-openssl-debuginfo Operating systems & Components / Operating system package or component php8-fileinfo Operating systems & Components / Operating system package or component php8-readline-debuginfo Operating systems & Components / Operating system package or component php8-fpm-debuginfo Operating systems & Components / Operating system package or component php8-xsl Operating systems & Components / Operating system package or component php8-openssl Operating systems & Components / Operating system package or component php8-tokenizer Operating systems & Components / Operating system package or component php8-soap-debuginfo Operating systems & Components / Operating system package or component php8-snmp Operating systems & Components / Operating system package or component php8-pgsql-debuginfo Operating systems & Components / Operating system package or component php8-sqlite-debuginfo Operating systems & Components / Operating system package or component php8-pdo-debuginfo Operating systems & Components / Operating system package or component php8-ctype Operating systems & Components / Operating system package or component php8-mysql-debuginfo Operating systems & Components / Operating system package or component php8-enchant-debuginfo Operating systems & Components / Operating system package or component php8-fastcgi-debugsource Operating systems & Components / Operating system package or component php8-ldap-debuginfo Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains information about 6 vulnerabilities.
EUVDB-ID: #VU105639
Risk: Medium
CVSSv4.0: 1.7 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-11235
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in the reference counter within php_request_shutdown function. A remote attacker can perform a denial of service (DoS) attack.
Update the affected package php8 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise High Performance Computing LTSS 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4 - SP5
SUSE Linux Enterprise Server 15 SP5: LTSS
SUSE Linux Enterprise Server 15 SP4: LTSS
SUSE Linux Enterprise Server for SAP Applications 15: SP4 - SP5
SUSE Linux Enterprise Server 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing 15: SP4 - SP5
SUSE Manager Server: 4.3
openSUSE Leap: 15.4
php8-phar: before 8.0.30-150400.4.54.1
php8-shmop: before 8.0.30-150400.4.54.1
php8-gd: before 8.0.30-150400.4.54.1
php8-pdo: before 8.0.30-150400.4.54.1
php8-embed-debugsource: before 8.0.30-150400.4.54.1
php8-embed: before 8.0.30-150400.4.54.1
php8-fpm: before 8.0.30-150400.4.54.1
php8-sockets: before 8.0.30-150400.4.54.1
php8-sodium-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc: before 8.0.30-150400.4.54.1
php8-fpm-debugsource: before 8.0.30-150400.4.54.1
php8-tokenizer-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib: before 8.0.30-150400.4.54.1
php8-dom-debuginfo: before 8.0.30-150400.4.54.1
apache2-mod_php8-debugsource: before 8.0.30-150400.4.54.1
php8-gettext: before 8.0.30-150400.4.54.1
php8-sysvsem-debuginfo: before 8.0.30-150400.4.54.1
php8-dba: before 8.0.30-150400.4.54.1
php8-bz2-debuginfo: before 8.0.30-150400.4.54.1
php8-curl: before 8.0.30-150400.4.54.1
php8-xmlreader-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi: before 8.0.30-150400.4.54.1
php8-sysvsem: before 8.0.30-150400.4.54.1
php8-cli: before 8.0.30-150400.4.54.1
php8-dom: before 8.0.30-150400.4.54.1
php8-gettext-debuginfo: before 8.0.30-150400.4.54.1
php8-tidy-debuginfo: before 8.0.30-150400.4.54.1
php8-pgsql: before 8.0.30-150400.4.54.1
php8-bcmath: before 8.0.30-150400.4.54.1
php8-posix: before 8.0.30-150400.4.54.1
php8-dba-debuginfo: before 8.0.30-150400.4.54.1
php8-bz2: before 8.0.30-150400.4.54.1
php8-shmop-debuginfo: before 8.0.30-150400.4.54.1
php8-gd-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl-debuginfo: before 8.0.30-150400.4.54.1
php8-sockets-debuginfo: before 8.0.30-150400.4.54.1
php8-calendar: before 8.0.30-150400.4.54.1
php8-embed-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib-debuginfo: before 8.0.30-150400.4.54.1
php8-sodium: before 8.0.30-150400.4.54.1
php8-intl: before 8.0.30-150400.4.54.1
php8-mbstring: before 8.0.30-150400.4.54.1
apache2-mod_php8-debuginfo: before 8.0.30-150400.4.54.1
php8-ftp-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp-debuginfo: before 8.0.30-150400.4.54.1
php8-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl: before 8.0.30-150400.4.54.1
php8-sysvshm: before 8.0.30-150400.4.54.1
php8-mbstring-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype-debuginfo: before 8.0.30-150400.4.54.1
php8-bcmath-debuginfo: before 8.0.30-150400.4.54.1
php8-devel: before 8.0.30-150400.4.54.1
php8-tidy: before 8.0.30-150400.4.54.1
php8-soap: before 8.0.30-150400.4.54.1
php8: before 8.0.30-150400.4.54.1
php8-zip-debuginfo: before 8.0.30-150400.4.54.1
php8-exif-debuginfo: before 8.0.30-150400.4.54.1
php8-curl-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache: before 8.0.30-150400.4.54.1
php8-mysql: before 8.0.30-150400.4.54.1
php8-test: before 8.0.30-150400.4.54.1
php8-iconv: before 8.0.30-150400.4.54.1
php8-readline: before 8.0.30-150400.4.54.1
php8-ftp: before 8.0.30-150400.4.54.1
php8-posix-debuginfo: before 8.0.30-150400.4.54.1
php8-intl-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite: before 8.0.30-150400.4.54.1
php8-iconv-debuginfo: before 8.0.30-150400.4.54.1
php8-debugsource: before 8.0.30-150400.4.54.1
php8-xmlreader: before 8.0.30-150400.4.54.1
php8-xmlwriter-debuginfo: before 8.0.30-150400.4.54.1
php8-xmlwriter: before 8.0.30-150400.4.54.1
php8-calendar-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache-debuginfo: before 8.0.30-150400.4.54.1
php8-zip: before 8.0.30-150400.4.54.1
php8-ldap: before 8.0.30-150400.4.54.1
php8-cli-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp: before 8.0.30-150400.4.54.1
php8-sysvmsg: before 8.0.30-150400.4.54.1
php8-enchant: before 8.0.30-150400.4.54.1
apache2-mod_php8: before 8.0.30-150400.4.54.1
php8-phar-debuginfo: before 8.0.30-150400.4.54.1
php8-sysvshm-debuginfo: before 8.0.30-150400.4.54.1
php8-exif: before 8.0.30-150400.4.54.1
php8-sysvmsg-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debuginfo: before 8.0.30-150400.4.54.1
php8-openssl-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo: before 8.0.30-150400.4.54.1
php8-readline-debuginfo: before 8.0.30-150400.4.54.1
php8-fpm-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl: before 8.0.30-150400.4.54.1
php8-openssl: before 8.0.30-150400.4.54.1
php8-tokenizer: before 8.0.30-150400.4.54.1
php8-soap-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp: before 8.0.30-150400.4.54.1
php8-pgsql-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite-debuginfo: before 8.0.30-150400.4.54.1
php8-pdo-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype: before 8.0.30-150400.4.54.1
php8-mysql-debuginfo: before 8.0.30-150400.4.54.1
php8-enchant-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debugsource: before 8.0.30-150400.4.54.1
php8-ldap-debuginfo: before 8.0.30-150400.4.54.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250994-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU105644
Risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-1217
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to Header parser of HTTP Stream wrapper does not handle folded headers. A remote attacker can perform spoofing attack by manipulating HTTP headers.
Update the affected package php8 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise High Performance Computing LTSS 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4 - SP5
SUSE Linux Enterprise Server 15 SP5: LTSS
SUSE Linux Enterprise Server 15 SP4: LTSS
SUSE Linux Enterprise Server for SAP Applications 15: SP4 - SP5
SUSE Linux Enterprise Server 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing 15: SP4 - SP5
SUSE Manager Server: 4.3
openSUSE Leap: 15.4
php8-phar: before 8.0.30-150400.4.54.1
php8-shmop: before 8.0.30-150400.4.54.1
php8-gd: before 8.0.30-150400.4.54.1
php8-pdo: before 8.0.30-150400.4.54.1
php8-embed-debugsource: before 8.0.30-150400.4.54.1
php8-embed: before 8.0.30-150400.4.54.1
php8-fpm: before 8.0.30-150400.4.54.1
php8-sockets: before 8.0.30-150400.4.54.1
php8-sodium-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc: before 8.0.30-150400.4.54.1
php8-fpm-debugsource: before 8.0.30-150400.4.54.1
php8-tokenizer-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib: before 8.0.30-150400.4.54.1
php8-dom-debuginfo: before 8.0.30-150400.4.54.1
apache2-mod_php8-debugsource: before 8.0.30-150400.4.54.1
php8-gettext: before 8.0.30-150400.4.54.1
php8-sysvsem-debuginfo: before 8.0.30-150400.4.54.1
php8-dba: before 8.0.30-150400.4.54.1
php8-bz2-debuginfo: before 8.0.30-150400.4.54.1
php8-curl: before 8.0.30-150400.4.54.1
php8-xmlreader-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi: before 8.0.30-150400.4.54.1
php8-sysvsem: before 8.0.30-150400.4.54.1
php8-cli: before 8.0.30-150400.4.54.1
php8-dom: before 8.0.30-150400.4.54.1
php8-gettext-debuginfo: before 8.0.30-150400.4.54.1
php8-tidy-debuginfo: before 8.0.30-150400.4.54.1
php8-pgsql: before 8.0.30-150400.4.54.1
php8-bcmath: before 8.0.30-150400.4.54.1
php8-posix: before 8.0.30-150400.4.54.1
php8-dba-debuginfo: before 8.0.30-150400.4.54.1
php8-bz2: before 8.0.30-150400.4.54.1
php8-shmop-debuginfo: before 8.0.30-150400.4.54.1
php8-gd-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl-debuginfo: before 8.0.30-150400.4.54.1
php8-sockets-debuginfo: before 8.0.30-150400.4.54.1
php8-calendar: before 8.0.30-150400.4.54.1
php8-embed-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib-debuginfo: before 8.0.30-150400.4.54.1
php8-sodium: before 8.0.30-150400.4.54.1
php8-intl: before 8.0.30-150400.4.54.1
php8-mbstring: before 8.0.30-150400.4.54.1
apache2-mod_php8-debuginfo: before 8.0.30-150400.4.54.1
php8-ftp-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp-debuginfo: before 8.0.30-150400.4.54.1
php8-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl: before 8.0.30-150400.4.54.1
php8-sysvshm: before 8.0.30-150400.4.54.1
php8-mbstring-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype-debuginfo: before 8.0.30-150400.4.54.1
php8-bcmath-debuginfo: before 8.0.30-150400.4.54.1
php8-devel: before 8.0.30-150400.4.54.1
php8-tidy: before 8.0.30-150400.4.54.1
php8-soap: before 8.0.30-150400.4.54.1
php8: before 8.0.30-150400.4.54.1
php8-zip-debuginfo: before 8.0.30-150400.4.54.1
php8-exif-debuginfo: before 8.0.30-150400.4.54.1
php8-curl-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache: before 8.0.30-150400.4.54.1
php8-mysql: before 8.0.30-150400.4.54.1
php8-test: before 8.0.30-150400.4.54.1
php8-iconv: before 8.0.30-150400.4.54.1
php8-readline: before 8.0.30-150400.4.54.1
php8-ftp: before 8.0.30-150400.4.54.1
php8-posix-debuginfo: before 8.0.30-150400.4.54.1
php8-intl-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite: before 8.0.30-150400.4.54.1
php8-iconv-debuginfo: before 8.0.30-150400.4.54.1
php8-debugsource: before 8.0.30-150400.4.54.1
php8-xmlreader: before 8.0.30-150400.4.54.1
php8-xmlwriter-debuginfo: before 8.0.30-150400.4.54.1
php8-xmlwriter: before 8.0.30-150400.4.54.1
php8-calendar-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache-debuginfo: before 8.0.30-150400.4.54.1
php8-zip: before 8.0.30-150400.4.54.1
php8-ldap: before 8.0.30-150400.4.54.1
php8-cli-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp: before 8.0.30-150400.4.54.1
php8-sysvmsg: before 8.0.30-150400.4.54.1
php8-enchant: before 8.0.30-150400.4.54.1
apache2-mod_php8: before 8.0.30-150400.4.54.1
php8-phar-debuginfo: before 8.0.30-150400.4.54.1
php8-sysvshm-debuginfo: before 8.0.30-150400.4.54.1
php8-exif: before 8.0.30-150400.4.54.1
php8-sysvmsg-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debuginfo: before 8.0.30-150400.4.54.1
php8-openssl-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo: before 8.0.30-150400.4.54.1
php8-readline-debuginfo: before 8.0.30-150400.4.54.1
php8-fpm-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl: before 8.0.30-150400.4.54.1
php8-openssl: before 8.0.30-150400.4.54.1
php8-tokenizer: before 8.0.30-150400.4.54.1
php8-soap-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp: before 8.0.30-150400.4.54.1
php8-pgsql-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite-debuginfo: before 8.0.30-150400.4.54.1
php8-pdo-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype: before 8.0.30-150400.4.54.1
php8-mysql-debuginfo: before 8.0.30-150400.4.54.1
php8-enchant-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debugsource: before 8.0.30-150400.4.54.1
php8-ldap-debuginfo: before 8.0.30-150400.4.54.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250994-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU105640
Risk: Low
CVSSv4.0: 0.5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-1219
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists in libxml streams due to usage of an incorrect Content-Type header when requesting a redirected resource. A remote attacker can leverage this vulnerability to perform content spoofing or XSS attacks.
Update the affected package php8 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise High Performance Computing LTSS 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4 - SP5
SUSE Linux Enterprise Server 15 SP5: LTSS
SUSE Linux Enterprise Server 15 SP4: LTSS
SUSE Linux Enterprise Server for SAP Applications 15: SP4 - SP5
SUSE Linux Enterprise Server 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing 15: SP4 - SP5
SUSE Manager Server: 4.3
openSUSE Leap: 15.4
php8-phar: before 8.0.30-150400.4.54.1
php8-shmop: before 8.0.30-150400.4.54.1
php8-gd: before 8.0.30-150400.4.54.1
php8-pdo: before 8.0.30-150400.4.54.1
php8-embed-debugsource: before 8.0.30-150400.4.54.1
php8-embed: before 8.0.30-150400.4.54.1
php8-fpm: before 8.0.30-150400.4.54.1
php8-sockets: before 8.0.30-150400.4.54.1
php8-sodium-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc: before 8.0.30-150400.4.54.1
php8-fpm-debugsource: before 8.0.30-150400.4.54.1
php8-tokenizer-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib: before 8.0.30-150400.4.54.1
php8-dom-debuginfo: before 8.0.30-150400.4.54.1
apache2-mod_php8-debugsource: before 8.0.30-150400.4.54.1
php8-gettext: before 8.0.30-150400.4.54.1
php8-sysvsem-debuginfo: before 8.0.30-150400.4.54.1
php8-dba: before 8.0.30-150400.4.54.1
php8-bz2-debuginfo: before 8.0.30-150400.4.54.1
php8-curl: before 8.0.30-150400.4.54.1
php8-xmlreader-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi: before 8.0.30-150400.4.54.1
php8-sysvsem: before 8.0.30-150400.4.54.1
php8-cli: before 8.0.30-150400.4.54.1
php8-dom: before 8.0.30-150400.4.54.1
php8-gettext-debuginfo: before 8.0.30-150400.4.54.1
php8-tidy-debuginfo: before 8.0.30-150400.4.54.1
php8-pgsql: before 8.0.30-150400.4.54.1
php8-bcmath: before 8.0.30-150400.4.54.1
php8-posix: before 8.0.30-150400.4.54.1
php8-dba-debuginfo: before 8.0.30-150400.4.54.1
php8-bz2: before 8.0.30-150400.4.54.1
php8-shmop-debuginfo: before 8.0.30-150400.4.54.1
php8-gd-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl-debuginfo: before 8.0.30-150400.4.54.1
php8-sockets-debuginfo: before 8.0.30-150400.4.54.1
php8-calendar: before 8.0.30-150400.4.54.1
php8-embed-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib-debuginfo: before 8.0.30-150400.4.54.1
php8-sodium: before 8.0.30-150400.4.54.1
php8-intl: before 8.0.30-150400.4.54.1
php8-mbstring: before 8.0.30-150400.4.54.1
apache2-mod_php8-debuginfo: before 8.0.30-150400.4.54.1
php8-ftp-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp-debuginfo: before 8.0.30-150400.4.54.1
php8-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl: before 8.0.30-150400.4.54.1
php8-sysvshm: before 8.0.30-150400.4.54.1
php8-mbstring-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype-debuginfo: before 8.0.30-150400.4.54.1
php8-bcmath-debuginfo: before 8.0.30-150400.4.54.1
php8-devel: before 8.0.30-150400.4.54.1
php8-tidy: before 8.0.30-150400.4.54.1
php8-soap: before 8.0.30-150400.4.54.1
php8: before 8.0.30-150400.4.54.1
php8-zip-debuginfo: before 8.0.30-150400.4.54.1
php8-exif-debuginfo: before 8.0.30-150400.4.54.1
php8-curl-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache: before 8.0.30-150400.4.54.1
php8-mysql: before 8.0.30-150400.4.54.1
php8-test: before 8.0.30-150400.4.54.1
php8-iconv: before 8.0.30-150400.4.54.1
php8-readline: before 8.0.30-150400.4.54.1
php8-ftp: before 8.0.30-150400.4.54.1
php8-posix-debuginfo: before 8.0.30-150400.4.54.1
php8-intl-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite: before 8.0.30-150400.4.54.1
php8-iconv-debuginfo: before 8.0.30-150400.4.54.1
php8-debugsource: before 8.0.30-150400.4.54.1
php8-xmlreader: before 8.0.30-150400.4.54.1
php8-xmlwriter-debuginfo: before 8.0.30-150400.4.54.1
php8-xmlwriter: before 8.0.30-150400.4.54.1
php8-calendar-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache-debuginfo: before 8.0.30-150400.4.54.1
php8-zip: before 8.0.30-150400.4.54.1
php8-ldap: before 8.0.30-150400.4.54.1
php8-cli-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp: before 8.0.30-150400.4.54.1
php8-sysvmsg: before 8.0.30-150400.4.54.1
php8-enchant: before 8.0.30-150400.4.54.1
apache2-mod_php8: before 8.0.30-150400.4.54.1
php8-phar-debuginfo: before 8.0.30-150400.4.54.1
php8-sysvshm-debuginfo: before 8.0.30-150400.4.54.1
php8-exif: before 8.0.30-150400.4.54.1
php8-sysvmsg-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debuginfo: before 8.0.30-150400.4.54.1
php8-openssl-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo: before 8.0.30-150400.4.54.1
php8-readline-debuginfo: before 8.0.30-150400.4.54.1
php8-fpm-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl: before 8.0.30-150400.4.54.1
php8-openssl: before 8.0.30-150400.4.54.1
php8-tokenizer: before 8.0.30-150400.4.54.1
php8-soap-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp: before 8.0.30-150400.4.54.1
php8-pgsql-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite-debuginfo: before 8.0.30-150400.4.54.1
php8-pdo-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype: before 8.0.30-150400.4.54.1
php8-mysql-debuginfo: before 8.0.30-150400.4.54.1
php8-enchant-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debugsource: before 8.0.30-150400.4.54.1
php8-ldap-debuginfo: before 8.0.30-150400.4.54.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250994-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU105643
Risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-1734
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the Streams HTTP wrapper does not fail for headers without a colon. A remote attacker can potentially perform header injection, which can lead to a spoofing attack.
MitigationUpdate the affected package php8 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise High Performance Computing LTSS 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4 - SP5
SUSE Linux Enterprise Server 15 SP5: LTSS
SUSE Linux Enterprise Server 15 SP4: LTSS
SUSE Linux Enterprise Server for SAP Applications 15: SP4 - SP5
SUSE Linux Enterprise Server 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing 15: SP4 - SP5
SUSE Manager Server: 4.3
openSUSE Leap: 15.4
php8-phar: before 8.0.30-150400.4.54.1
php8-shmop: before 8.0.30-150400.4.54.1
php8-gd: before 8.0.30-150400.4.54.1
php8-pdo: before 8.0.30-150400.4.54.1
php8-embed-debugsource: before 8.0.30-150400.4.54.1
php8-embed: before 8.0.30-150400.4.54.1
php8-fpm: before 8.0.30-150400.4.54.1
php8-sockets: before 8.0.30-150400.4.54.1
php8-sodium-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc: before 8.0.30-150400.4.54.1
php8-fpm-debugsource: before 8.0.30-150400.4.54.1
php8-tokenizer-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib: before 8.0.30-150400.4.54.1
php8-dom-debuginfo: before 8.0.30-150400.4.54.1
apache2-mod_php8-debugsource: before 8.0.30-150400.4.54.1
php8-gettext: before 8.0.30-150400.4.54.1
php8-sysvsem-debuginfo: before 8.0.30-150400.4.54.1
php8-dba: before 8.0.30-150400.4.54.1
php8-bz2-debuginfo: before 8.0.30-150400.4.54.1
php8-curl: before 8.0.30-150400.4.54.1
php8-xmlreader-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi: before 8.0.30-150400.4.54.1
php8-sysvsem: before 8.0.30-150400.4.54.1
php8-cli: before 8.0.30-150400.4.54.1
php8-dom: before 8.0.30-150400.4.54.1
php8-gettext-debuginfo: before 8.0.30-150400.4.54.1
php8-tidy-debuginfo: before 8.0.30-150400.4.54.1
php8-pgsql: before 8.0.30-150400.4.54.1
php8-bcmath: before 8.0.30-150400.4.54.1
php8-posix: before 8.0.30-150400.4.54.1
php8-dba-debuginfo: before 8.0.30-150400.4.54.1
php8-bz2: before 8.0.30-150400.4.54.1
php8-shmop-debuginfo: before 8.0.30-150400.4.54.1
php8-gd-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl-debuginfo: before 8.0.30-150400.4.54.1
php8-sockets-debuginfo: before 8.0.30-150400.4.54.1
php8-calendar: before 8.0.30-150400.4.54.1
php8-embed-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib-debuginfo: before 8.0.30-150400.4.54.1
php8-sodium: before 8.0.30-150400.4.54.1
php8-intl: before 8.0.30-150400.4.54.1
php8-mbstring: before 8.0.30-150400.4.54.1
apache2-mod_php8-debuginfo: before 8.0.30-150400.4.54.1
php8-ftp-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp-debuginfo: before 8.0.30-150400.4.54.1
php8-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl: before 8.0.30-150400.4.54.1
php8-sysvshm: before 8.0.30-150400.4.54.1
php8-mbstring-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype-debuginfo: before 8.0.30-150400.4.54.1
php8-bcmath-debuginfo: before 8.0.30-150400.4.54.1
php8-devel: before 8.0.30-150400.4.54.1
php8-tidy: before 8.0.30-150400.4.54.1
php8-soap: before 8.0.30-150400.4.54.1
php8: before 8.0.30-150400.4.54.1
php8-zip-debuginfo: before 8.0.30-150400.4.54.1
php8-exif-debuginfo: before 8.0.30-150400.4.54.1
php8-curl-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache: before 8.0.30-150400.4.54.1
php8-mysql: before 8.0.30-150400.4.54.1
php8-test: before 8.0.30-150400.4.54.1
php8-iconv: before 8.0.30-150400.4.54.1
php8-readline: before 8.0.30-150400.4.54.1
php8-ftp: before 8.0.30-150400.4.54.1
php8-posix-debuginfo: before 8.0.30-150400.4.54.1
php8-intl-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite: before 8.0.30-150400.4.54.1
php8-iconv-debuginfo: before 8.0.30-150400.4.54.1
php8-debugsource: before 8.0.30-150400.4.54.1
php8-xmlreader: before 8.0.30-150400.4.54.1
php8-xmlwriter-debuginfo: before 8.0.30-150400.4.54.1
php8-xmlwriter: before 8.0.30-150400.4.54.1
php8-calendar-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache-debuginfo: before 8.0.30-150400.4.54.1
php8-zip: before 8.0.30-150400.4.54.1
php8-ldap: before 8.0.30-150400.4.54.1
php8-cli-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp: before 8.0.30-150400.4.54.1
php8-sysvmsg: before 8.0.30-150400.4.54.1
php8-enchant: before 8.0.30-150400.4.54.1
apache2-mod_php8: before 8.0.30-150400.4.54.1
php8-phar-debuginfo: before 8.0.30-150400.4.54.1
php8-sysvshm-debuginfo: before 8.0.30-150400.4.54.1
php8-exif: before 8.0.30-150400.4.54.1
php8-sysvmsg-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debuginfo: before 8.0.30-150400.4.54.1
php8-openssl-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo: before 8.0.30-150400.4.54.1
php8-readline-debuginfo: before 8.0.30-150400.4.54.1
php8-fpm-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl: before 8.0.30-150400.4.54.1
php8-openssl: before 8.0.30-150400.4.54.1
php8-tokenizer: before 8.0.30-150400.4.54.1
php8-soap-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp: before 8.0.30-150400.4.54.1
php8-pgsql-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite-debuginfo: before 8.0.30-150400.4.54.1
php8-pdo-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype: before 8.0.30-150400.4.54.1
php8-mysql-debuginfo: before 8.0.30-150400.4.54.1
php8-enchant-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debugsource: before 8.0.30-150400.4.54.1
php8-ldap-debuginfo: before 8.0.30-150400.4.54.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250994-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU105641
Risk: Medium
CVSSv4.0: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-1736
CWE-ID:
CWE-287 - Improper Authentication
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in Stream HTTP wrapper header check, which can omit Basic authentication header. A remote attacker can bypass authentication mechanisms that rely on Basic authentication.
Update the affected package php8 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise High Performance Computing LTSS 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4 - SP5
SUSE Linux Enterprise Server 15 SP5: LTSS
SUSE Linux Enterprise Server 15 SP4: LTSS
SUSE Linux Enterprise Server for SAP Applications 15: SP4 - SP5
SUSE Linux Enterprise Server 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing 15: SP4 - SP5
SUSE Manager Server: 4.3
openSUSE Leap: 15.4
php8-phar: before 8.0.30-150400.4.54.1
php8-shmop: before 8.0.30-150400.4.54.1
php8-gd: before 8.0.30-150400.4.54.1
php8-pdo: before 8.0.30-150400.4.54.1
php8-embed-debugsource: before 8.0.30-150400.4.54.1
php8-embed: before 8.0.30-150400.4.54.1
php8-fpm: before 8.0.30-150400.4.54.1
php8-sockets: before 8.0.30-150400.4.54.1
php8-sodium-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc: before 8.0.30-150400.4.54.1
php8-fpm-debugsource: before 8.0.30-150400.4.54.1
php8-tokenizer-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib: before 8.0.30-150400.4.54.1
php8-dom-debuginfo: before 8.0.30-150400.4.54.1
apache2-mod_php8-debugsource: before 8.0.30-150400.4.54.1
php8-gettext: before 8.0.30-150400.4.54.1
php8-sysvsem-debuginfo: before 8.0.30-150400.4.54.1
php8-dba: before 8.0.30-150400.4.54.1
php8-bz2-debuginfo: before 8.0.30-150400.4.54.1
php8-curl: before 8.0.30-150400.4.54.1
php8-xmlreader-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi: before 8.0.30-150400.4.54.1
php8-sysvsem: before 8.0.30-150400.4.54.1
php8-cli: before 8.0.30-150400.4.54.1
php8-dom: before 8.0.30-150400.4.54.1
php8-gettext-debuginfo: before 8.0.30-150400.4.54.1
php8-tidy-debuginfo: before 8.0.30-150400.4.54.1
php8-pgsql: before 8.0.30-150400.4.54.1
php8-bcmath: before 8.0.30-150400.4.54.1
php8-posix: before 8.0.30-150400.4.54.1
php8-dba-debuginfo: before 8.0.30-150400.4.54.1
php8-bz2: before 8.0.30-150400.4.54.1
php8-shmop-debuginfo: before 8.0.30-150400.4.54.1
php8-gd-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl-debuginfo: before 8.0.30-150400.4.54.1
php8-sockets-debuginfo: before 8.0.30-150400.4.54.1
php8-calendar: before 8.0.30-150400.4.54.1
php8-embed-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib-debuginfo: before 8.0.30-150400.4.54.1
php8-sodium: before 8.0.30-150400.4.54.1
php8-intl: before 8.0.30-150400.4.54.1
php8-mbstring: before 8.0.30-150400.4.54.1
apache2-mod_php8-debuginfo: before 8.0.30-150400.4.54.1
php8-ftp-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp-debuginfo: before 8.0.30-150400.4.54.1
php8-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl: before 8.0.30-150400.4.54.1
php8-sysvshm: before 8.0.30-150400.4.54.1
php8-mbstring-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype-debuginfo: before 8.0.30-150400.4.54.1
php8-bcmath-debuginfo: before 8.0.30-150400.4.54.1
php8-devel: before 8.0.30-150400.4.54.1
php8-tidy: before 8.0.30-150400.4.54.1
php8-soap: before 8.0.30-150400.4.54.1
php8: before 8.0.30-150400.4.54.1
php8-zip-debuginfo: before 8.0.30-150400.4.54.1
php8-exif-debuginfo: before 8.0.30-150400.4.54.1
php8-curl-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache: before 8.0.30-150400.4.54.1
php8-mysql: before 8.0.30-150400.4.54.1
php8-test: before 8.0.30-150400.4.54.1
php8-iconv: before 8.0.30-150400.4.54.1
php8-readline: before 8.0.30-150400.4.54.1
php8-ftp: before 8.0.30-150400.4.54.1
php8-posix-debuginfo: before 8.0.30-150400.4.54.1
php8-intl-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite: before 8.0.30-150400.4.54.1
php8-iconv-debuginfo: before 8.0.30-150400.4.54.1
php8-debugsource: before 8.0.30-150400.4.54.1
php8-xmlreader: before 8.0.30-150400.4.54.1
php8-xmlwriter-debuginfo: before 8.0.30-150400.4.54.1
php8-xmlwriter: before 8.0.30-150400.4.54.1
php8-calendar-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache-debuginfo: before 8.0.30-150400.4.54.1
php8-zip: before 8.0.30-150400.4.54.1
php8-ldap: before 8.0.30-150400.4.54.1
php8-cli-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp: before 8.0.30-150400.4.54.1
php8-sysvmsg: before 8.0.30-150400.4.54.1
php8-enchant: before 8.0.30-150400.4.54.1
apache2-mod_php8: before 8.0.30-150400.4.54.1
php8-phar-debuginfo: before 8.0.30-150400.4.54.1
php8-sysvshm-debuginfo: before 8.0.30-150400.4.54.1
php8-exif: before 8.0.30-150400.4.54.1
php8-sysvmsg-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debuginfo: before 8.0.30-150400.4.54.1
php8-openssl-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo: before 8.0.30-150400.4.54.1
php8-readline-debuginfo: before 8.0.30-150400.4.54.1
php8-fpm-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl: before 8.0.30-150400.4.54.1
php8-openssl: before 8.0.30-150400.4.54.1
php8-tokenizer: before 8.0.30-150400.4.54.1
php8-soap-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp: before 8.0.30-150400.4.54.1
php8-pgsql-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite-debuginfo: before 8.0.30-150400.4.54.1
php8-pdo-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype: before 8.0.30-150400.4.54.1
php8-mysql-debuginfo: before 8.0.30-150400.4.54.1
php8-enchant-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debugsource: before 8.0.30-150400.4.54.1
php8-ldap-debuginfo: before 8.0.30-150400.4.54.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250994-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU105642
Risk: Low
CVSSv4.0: 0.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-1861
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to redirect the application to a malicious URL.
The vulnerability exists due to insufficient validation of user-supplied input. The Stream HTTP wrapper truncates redirect location to 1024 bytes, which can lead to the application being redirected to a wrong URL.
MitigationUpdate the affected package php8 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise High Performance Computing LTSS 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4 - SP5
SUSE Linux Enterprise Server 15 SP5: LTSS
SUSE Linux Enterprise Server 15 SP4: LTSS
SUSE Linux Enterprise Server for SAP Applications 15: SP4 - SP5
SUSE Linux Enterprise Server 15: SP4 - SP5
SUSE Linux Enterprise High Performance Computing 15: SP4 - SP5
SUSE Manager Server: 4.3
openSUSE Leap: 15.4
php8-phar: before 8.0.30-150400.4.54.1
php8-shmop: before 8.0.30-150400.4.54.1
php8-gd: before 8.0.30-150400.4.54.1
php8-pdo: before 8.0.30-150400.4.54.1
php8-embed-debugsource: before 8.0.30-150400.4.54.1
php8-embed: before 8.0.30-150400.4.54.1
php8-fpm: before 8.0.30-150400.4.54.1
php8-sockets: before 8.0.30-150400.4.54.1
php8-sodium-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc: before 8.0.30-150400.4.54.1
php8-fpm-debugsource: before 8.0.30-150400.4.54.1
php8-tokenizer-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib: before 8.0.30-150400.4.54.1
php8-dom-debuginfo: before 8.0.30-150400.4.54.1
apache2-mod_php8-debugsource: before 8.0.30-150400.4.54.1
php8-gettext: before 8.0.30-150400.4.54.1
php8-sysvsem-debuginfo: before 8.0.30-150400.4.54.1
php8-dba: before 8.0.30-150400.4.54.1
php8-bz2-debuginfo: before 8.0.30-150400.4.54.1
php8-curl: before 8.0.30-150400.4.54.1
php8-xmlreader-debuginfo: before 8.0.30-150400.4.54.1
php8-odbc-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi: before 8.0.30-150400.4.54.1
php8-sysvsem: before 8.0.30-150400.4.54.1
php8-cli: before 8.0.30-150400.4.54.1
php8-dom: before 8.0.30-150400.4.54.1
php8-gettext-debuginfo: before 8.0.30-150400.4.54.1
php8-tidy-debuginfo: before 8.0.30-150400.4.54.1
php8-pgsql: before 8.0.30-150400.4.54.1
php8-bcmath: before 8.0.30-150400.4.54.1
php8-posix: before 8.0.30-150400.4.54.1
php8-dba-debuginfo: before 8.0.30-150400.4.54.1
php8-bz2: before 8.0.30-150400.4.54.1
php8-shmop-debuginfo: before 8.0.30-150400.4.54.1
php8-gd-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl-debuginfo: before 8.0.30-150400.4.54.1
php8-sockets-debuginfo: before 8.0.30-150400.4.54.1
php8-calendar: before 8.0.30-150400.4.54.1
php8-embed-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo-debuginfo: before 8.0.30-150400.4.54.1
php8-zlib-debuginfo: before 8.0.30-150400.4.54.1
php8-sodium: before 8.0.30-150400.4.54.1
php8-intl: before 8.0.30-150400.4.54.1
php8-mbstring: before 8.0.30-150400.4.54.1
apache2-mod_php8-debuginfo: before 8.0.30-150400.4.54.1
php8-ftp-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp-debuginfo: before 8.0.30-150400.4.54.1
php8-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl: before 8.0.30-150400.4.54.1
php8-sysvshm: before 8.0.30-150400.4.54.1
php8-mbstring-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype-debuginfo: before 8.0.30-150400.4.54.1
php8-bcmath-debuginfo: before 8.0.30-150400.4.54.1
php8-devel: before 8.0.30-150400.4.54.1
php8-tidy: before 8.0.30-150400.4.54.1
php8-soap: before 8.0.30-150400.4.54.1
php8: before 8.0.30-150400.4.54.1
php8-zip-debuginfo: before 8.0.30-150400.4.54.1
php8-exif-debuginfo: before 8.0.30-150400.4.54.1
php8-curl-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache: before 8.0.30-150400.4.54.1
php8-mysql: before 8.0.30-150400.4.54.1
php8-test: before 8.0.30-150400.4.54.1
php8-iconv: before 8.0.30-150400.4.54.1
php8-readline: before 8.0.30-150400.4.54.1
php8-ftp: before 8.0.30-150400.4.54.1
php8-posix-debuginfo: before 8.0.30-150400.4.54.1
php8-intl-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite: before 8.0.30-150400.4.54.1
php8-iconv-debuginfo: before 8.0.30-150400.4.54.1
php8-debugsource: before 8.0.30-150400.4.54.1
php8-xmlreader: before 8.0.30-150400.4.54.1
php8-xmlwriter-debuginfo: before 8.0.30-150400.4.54.1
php8-xmlwriter: before 8.0.30-150400.4.54.1
php8-calendar-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp-debuginfo: before 8.0.30-150400.4.54.1
php8-opcache-debuginfo: before 8.0.30-150400.4.54.1
php8-zip: before 8.0.30-150400.4.54.1
php8-ldap: before 8.0.30-150400.4.54.1
php8-cli-debuginfo: before 8.0.30-150400.4.54.1
php8-pcntl-debuginfo: before 8.0.30-150400.4.54.1
php8-gmp: before 8.0.30-150400.4.54.1
php8-sysvmsg: before 8.0.30-150400.4.54.1
php8-enchant: before 8.0.30-150400.4.54.1
apache2-mod_php8: before 8.0.30-150400.4.54.1
php8-phar-debuginfo: before 8.0.30-150400.4.54.1
php8-sysvshm-debuginfo: before 8.0.30-150400.4.54.1
php8-exif: before 8.0.30-150400.4.54.1
php8-sysvmsg-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debuginfo: before 8.0.30-150400.4.54.1
php8-openssl-debuginfo: before 8.0.30-150400.4.54.1
php8-fileinfo: before 8.0.30-150400.4.54.1
php8-readline-debuginfo: before 8.0.30-150400.4.54.1
php8-fpm-debuginfo: before 8.0.30-150400.4.54.1
php8-xsl: before 8.0.30-150400.4.54.1
php8-openssl: before 8.0.30-150400.4.54.1
php8-tokenizer: before 8.0.30-150400.4.54.1
php8-soap-debuginfo: before 8.0.30-150400.4.54.1
php8-snmp: before 8.0.30-150400.4.54.1
php8-pgsql-debuginfo: before 8.0.30-150400.4.54.1
php8-sqlite-debuginfo: before 8.0.30-150400.4.54.1
php8-pdo-debuginfo: before 8.0.30-150400.4.54.1
php8-ctype: before 8.0.30-150400.4.54.1
php8-mysql-debuginfo: before 8.0.30-150400.4.54.1
php8-enchant-debuginfo: before 8.0.30-150400.4.54.1
php8-fastcgi-debugsource: before 8.0.30-150400.4.54.1
php8-ldap-debuginfo: before 8.0.30-150400.4.54.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250994-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.