Debian DLA-4819:libapache2-mod-php8.2 - 安全更新

medium Nessus 插件 ID 362914

简介

远程 Debian 主机上缺少一个或多个与安全性相关的更新。

描述

远程 Debian 12 主机上存在安装的程序包,该程序包受到 DLA-4819 公告中提及的多个漏洞的影响。

------------------------------------------------------------------------- Debian LTS 公告 DLA-4819-1 [email protected] https://www.debian.org/lts/security/Guilhem Moulin 2026 年 10 月 5 日 https://wiki.debian.org/LTS-------------------------------------------------------------------------

程序包:php8.2 版本:8.2.34-1~deb12u1 CVE ID: CVE-2025-1218 CVE-2025-14181 CVE-2026-6103 CVE-2026-91765 CVE-2026-91766 CVE-2026-91767 CVE-2026-91768 CVE-2026-91769 CVE-2026-92842 CVE-2026-93682

广泛使用的开源通用脚本语言 PHP 中发现多个安全问题,可能会造成拒绝服务、信息泄露、权限提升、TLS 证书验证不正确或访问控制限制绕过。

CVE-2025-1218

mysqlnd 线路协议中发现多个数据包越界读取,可能会在连接到不受信任或遭到破坏的 MySQL 服务器时导致拒绝服务。仅连接到受信任的数据库服务器的应用程序不会暴露。

CVE-2025-14181

SOAP HTTP 客户端通过依赖有符号的整数溢出检查保护其响应缓冲区增长,这可能导致拒绝服务或内存损坏,具体取决于堆布局和用于构建 PHP 的编译器。

CVE-2026-6103

在 phar_tar_number() 中发现一个整数溢出漏洞,可允许注入 TAR 存档条目。

CVE-2026-91765

已发现 SOAP XML 解析器中的 cleanup_xml_node() 函数在每个 XML 嵌套级别递归一次,没有深度限制,这可能允许通过构建的 SOAP 请求造成拒绝服务。

CVE-2026-91766

已发现 http:// 流封装程序在重定向到另一主机/端口或方案降级时泄漏凭据,这可能导致信息泄露或权限升级。

CVE-2026-91767

Mohamed Sayed 发现通过 TLS 连接到显示构建的通配符 CN 的服务器的客户端可在主机名验证期间造成无限长度的越界读取,从而导致拒绝服务。

CVE-2026-91768

发现 FastCGI 客户端访问检查的 IPv6 分支仅比较 16 字节 IPv6 地址的前 12 字节,因此“listen.allowed_clients”在 /96 前缀而不是确切地址上运行,这可能导致能够搜寻与允许的地址共享前 96 位的地址的攻击者绕过访问控制。

CVE-2026-91769

已发现 TLS 对等机验证违反 RFC 6125,在 subjectAltName 不匹配之后会回退到公用名验证。

CVE-2026-92842

当“line-break-chars”选项包含 NUL 时,convert.* 流会过滤掉 convert.* 流中的越界读取。

CVE-2026-93682

Ilia Alshanetsky 发现,跟随带有空 Location 标头的重定向时,HTTP 流封装程序中存在越界读取。

GHSA-ch8v-r6jh-4vvr

Khashayar Fereidani 发现 php_filter_encode_url() 未初始化其 256 条目查找表的最后一个条目。


对于 Debian 12 bookworm,这些问题已在 8.2.34-1~deb12u1 版本中修复。

我们建议您升级 php8.2 程序包。

如需了解 php8.2 的详细安全状态,请参阅其安全跟踪页面:
https://security-tracker.debian.org/tracker/php8.2

有关 Debian LTS 安全公告、如何将这些更新应用到系统以及常见问题解答的更多信息,请访问以下网址:https://wiki.debian.org/LTSAttachment:signature.ascDescription: PGP signature

Tenable 已直接从 Debian 安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

升级 libapache2-mod-php8.2 程序包。

另见

https://packages.debian.org/source/bookworm/php8.2

https://security-tracker.debian.org/tracker/CVE-2025-1218

https://security-tracker.debian.org/tracker/CVE-2025-14181

https://security-tracker.debian.org/tracker/CVE-2026-6103

https://security-tracker.debian.org/tracker/CVE-2026-91765

https://security-tracker.debian.org/tracker/CVE-2026-91766

https://security-tracker.debian.org/tracker/CVE-2026-91767

https://security-tracker.debian.org/tracker/CVE-2026-91768

https://security-tracker.debian.org/tracker/CVE-2026-91769

https://security-tracker.debian.org/tracker/CVE-2026-92842

https://security-tracker.debian.org/tracker/CVE-2026-93682

https://security-tracker.debian.org/tracker/source-package/php8.2

插件详情

严重性: Medium

ID: 362914

文件名: debian_DLA-4819.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/10/4

最近更新时间: 2026/10/4

支持的传感器: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: Low

分数: 3.5

百分位: 51.46

CVSS v2

风险因素: Medium

基本分数: 6.1

时间分数: 4.5

矢量: CVSS2#AV:A/AC:L/Au:N/C:C/I:N/A:N

CVSS 分数来源: CVE-2026-91768

CVSS v3

风险因素: Medium

基本分数: 6.5

时间分数: 5.7

矢量: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

漏洞信息

CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:libapache2-mod-php8.2, p-cpe:/a:debian:debian_linux:libphp8.2-embed, p-cpe:/a:debian:debian_linux:php8.2-bcmath, p-cpe:/a:debian:debian_linux:php8.2-bz2, p-cpe:/a:debian:debian_linux:php8.2-cgi, p-cpe:/a:debian:debian_linux:php8.2-cli, p-cpe:/a:debian:debian_linux:php8.2-common, p-cpe:/a:debian:debian_linux:php8.2-curl, p-cpe:/a:debian:debian_linux:php8.2-dba, p-cpe:/a:debian:debian_linux:php8.2-dev, p-cpe:/a:debian:debian_linux:php8.2-enchant, p-cpe:/a:debian:debian_linux:php8.2-fpm, p-cpe:/a:debian:debian_linux:php8.2-gd, p-cpe:/a:debian:debian_linux:php8.2-gmp, p-cpe:/a:debian:debian_linux:php8.2-imap, p-cpe:/a:debian:debian_linux:php8.2-interbase, p-cpe:/a:debian:debian_linux:php8.2-intl, p-cpe:/a:debian:debian_linux:php8.2-ldap, p-cpe:/a:debian:debian_linux:php8.2-mbstring, p-cpe:/a:debian:debian_linux:php8.2-mysql, p-cpe:/a:debian:debian_linux:php8.2-odbc, p-cpe:/a:debian:debian_linux:php8.2-opcache, p-cpe:/a:debian:debian_linux:php8.2-pgsql, p-cpe:/a:debian:debian_linux:php8.2-phpdbg, p-cpe:/a:debian:debian_linux:php8.2-pspell, p-cpe:/a:debian:debian_linux:php8.2-readline, p-cpe:/a:debian:debian_linux:php8.2-snmp, p-cpe:/a:debian:debian_linux:php8.2-soap, p-cpe:/a:debian:debian_linux:php8.2-sqlite3, p-cpe:/a:debian:debian_linux:php8.2-sybase, p-cpe:/a:debian:debian_linux:php8.2-tidy, p-cpe:/a:debian:debian_linux:php8.2-xml, p-cpe:/a:debian:debian_linux:php8.2-xsl, p-cpe:/a:debian:debian_linux:php8.2-zip, p-cpe:/a:debian:debian_linux:php8.2

必需的 KB 项: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

易利用性: No known exploits are available

补丁发布日期: 2026/10/5

漏洞发布日期: 2026/9/22

参考资料信息

CVE: CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, CVE-2026-93682