just installed php-fpm + nginx on a 20.04 system today (2021-12-05)
which installed 7.4.3-4ubuntu2.7 , which seems vulnerable, POC code
still causes segfaults:
https://github.com/cfreal/exploits/blob/master/php-SplDoublyLinkedList-
offsetUnset/exploit.php

i don't think this is fixed yet? at least not on 20.04

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1948957

Title:
  CVE-2021-21703: PHP-FPM oob R/W in root process leading to privilege
  escalation

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/php7.4/+bug/1948957/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to