Vulnerability Scan Report for registry.suse.com/bci/php-fpm:8.2.20
PHP-FPM 8 container based on the SLE Base Container Image.
Last scanned on: March 03, 2025 00:01

PHP-FPM 8 container based on the SLE Base Container Image.
Last scanned on: March 03, 2025 00:01
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
libtasn1-6 | HIGH | fixed |
Security update for libtasn1 Vulnerability ID: SUSE-SU-2025:0548-1 Installed Version: 4.13-150000.4.8.1 Fixed Version: 4.13-150000.4.11.1 This update for libtasn1 fixes the following issues: - CVE-2024-12133: the processing of input DER data containing a large number of SEQUENCE OF or SET OF elements takes quadratic time to complete. (bsc#1236878) |
||
libxml2-2 | HIGH | fixed |
Security update for libxml2 Vulnerability ID: SUSE-SU-2025:0348-1 Installed Version: 2.10.3-150500.5.17.1 Fixed Version: 2.10.3-150500.5.20.1 This update for libxml2 fixes the following issues: - CVE-2022-49043: Fixed a use-after-free in xmlXIncludeAddNode. (bsc#1236460) |
||
libxml2-2 | HIGH | fixed |
Security update for libxml2 Vulnerability ID: SUSE-SU-2025:0746-1 Installed Version: 2.10.3-150500.5.17.1 Fixed Version: 2.10.3-150500.5.23.1 This update for libxml2 fixes the following issues: - CVE-2024-56171: use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c (bsc#1237363). - CVE-2025-24928: stack-based buffer overflow in xmlSnprintfElements in valid.c (bsc#1237370). - CVE-2025-27113: NULL pointer dereference in xmlPatMatch in pattern.c (bsc#1237418). |
||
openssl-3 | MEDIUM | fixed |
Security update for openssl-3 Vulnerability ID: SUSE-SU-2024:3943-1 Installed Version: 3.1.4-150600.5.18.1 Fixed Version: 3.1.4-150600.5.21.1 This update for openssl-3 fixes the following issues: - CVE-2023-50782: Implicit rejection in PKCS#1 v1.5 (bsc#1220262) |
||
openssl-3 | MEDIUM | fixed |
Security update for openssl-3 Vulnerability ID: SUSE-SU-2025:0430-1 Installed Version: 3.1.4-150600.5.18.1 Fixed Version: 3.1.4-150600.5.24.1 This update for openssl-3 fixes the following issues: - CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation (bsc#1236136). |