<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for php74</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2022:4068-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2022-11-18T10:55:22Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2022-11-18T10:55:22Z</InitialReleaseDate>
    <CurrentReleaseDate>2022-11-18T10:55:22Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for php74</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for php74 fixes the following issues:

- Version update to 7.4.33:
- CVE-2022-31630: Fixed out-of-bounds read due to insufficient input validation in imageloadfont() (bsc#1204979).
- CVE-2022-37454: Fixed buffer overflow in hash_update() on long parameter (bsc#1204577).

- Version update to 7.4.32 (jsc#SLE-23639)
- CVE-2022-31628: Fixed an uncontrolled recursion in the phar uncompressor while decompressing 'quines' gzip files. (bsc#1203867)
- CVE-2022-31629: Fixed a bug which could lead an attacker to set an insecure cookie that will treated as secure in the victim's browser. (bsc#1203870)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2022-4068,SUSE-SLE-Module-Web-Scripting-12-2022-4068,SUSE-SLE-SDK-12-SP5-2022-4068</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      <Description>Link for SUSE-SU-2022:4068-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2022-November/012984.html</URL>
      <Description>E-Mail link for SUSE-SU-2022:4068-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1203867</URL>
      <Description>SUSE Bug 1203867</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1203870</URL>
      <Description>SUSE Bug 1203870</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1204577</URL>
      <Description>SUSE Bug 1204577</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1204979</URL>
      <Description>SUSE Bug 1204979</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-8923/</URL>
      <Description>SUSE CVE CVE-2017-8923 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-7068/</URL>
      <Description>SUSE CVE CVE-2020-7068 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-7069/</URL>
      <Description>SUSE CVE CVE-2020-7069 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-7070/</URL>
      <Description>SUSE CVE CVE-2020-7070 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-7071/</URL>
      <Description>SUSE CVE CVE-2020-7071 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21702/</URL>
      <Description>SUSE CVE CVE-2021-21702 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21703/</URL>
      <Description>SUSE CVE CVE-2021-21703 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21704/</URL>
      <Description>SUSE CVE CVE-2021-21704 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21705/</URL>
      <Description>SUSE CVE CVE-2021-21705 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21706/</URL>
      <Description>SUSE CVE CVE-2021-21706 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21707/</URL>
      <Description>SUSE CVE CVE-2021-21707 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21708/</URL>
      <Description>SUSE CVE CVE-2021-21708 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-31625/</URL>
      <Description>SUSE CVE CVE-2022-31625 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-31626/</URL>
      <Description>SUSE CVE CVE-2022-31626 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-31628/</URL>
      <Description>SUSE CVE CVE-2022-31628 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-31629/</URL>
      <Description>SUSE CVE CVE-2022-31629 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-31630/</URL>
      <Description>SUSE CVE CVE-2022-31630 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-37454/</URL>
      <Description>SUSE CVE CVE-2022-37454 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP5" CPE="cpe:/o:suse:sle-sdk:12:sp5">SUSE Linux Enterprise Software Development Kit 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="apache2-mod_php74-7.4.33-1.47.2">
      <FullProductName ProductID="apache2-mod_php74-7.4.33-1.47.2">apache2-mod_php74-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-7.4.33-1.47.2">
      <FullProductName ProductID="php74-7.4.33-1.47.2">php74-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-bcmath-7.4.33-1.47.2">
      <FullProductName ProductID="php74-bcmath-7.4.33-1.47.2">php74-bcmath-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-bz2-7.4.33-1.47.2">
      <FullProductName ProductID="php74-bz2-7.4.33-1.47.2">php74-bz2-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-calendar-7.4.33-1.47.2">
      <FullProductName ProductID="php74-calendar-7.4.33-1.47.2">php74-calendar-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-ctype-7.4.33-1.47.2">
      <FullProductName ProductID="php74-ctype-7.4.33-1.47.2">php74-ctype-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-curl-7.4.33-1.47.2">
      <FullProductName ProductID="php74-curl-7.4.33-1.47.2">php74-curl-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-dba-7.4.33-1.47.2">
      <FullProductName ProductID="php74-dba-7.4.33-1.47.2">php74-dba-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-devel-7.4.33-1.47.2">
      <FullProductName ProductID="php74-devel-7.4.33-1.47.2">php74-devel-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-dom-7.4.33-1.47.2">
      <FullProductName ProductID="php74-dom-7.4.33-1.47.2">php74-dom-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-embed-7.4.33-1.47.2">
      <FullProductName ProductID="php74-embed-7.4.33-1.47.2">php74-embed-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-enchant-7.4.33-1.47.2">
      <FullProductName ProductID="php74-enchant-7.4.33-1.47.2">php74-enchant-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-exif-7.4.33-1.47.2">
      <FullProductName ProductID="php74-exif-7.4.33-1.47.2">php74-exif-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-fastcgi-7.4.33-1.47.2">
      <FullProductName ProductID="php74-fastcgi-7.4.33-1.47.2">php74-fastcgi-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-fileinfo-7.4.33-1.47.2">
      <FullProductName ProductID="php74-fileinfo-7.4.33-1.47.2">php74-fileinfo-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-firebird-7.4.33-1.47.2">
      <FullProductName ProductID="php74-firebird-7.4.33-1.47.2">php74-firebird-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-fpm-7.4.33-1.47.2">
      <FullProductName ProductID="php74-fpm-7.4.33-1.47.2">php74-fpm-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-ftp-7.4.33-1.47.2">
      <FullProductName ProductID="php74-ftp-7.4.33-1.47.2">php74-ftp-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-gd-7.4.33-1.47.2">
      <FullProductName ProductID="php74-gd-7.4.33-1.47.2">php74-gd-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-gettext-7.4.33-1.47.2">
      <FullProductName ProductID="php74-gettext-7.4.33-1.47.2">php74-gettext-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-gmp-7.4.33-1.47.2">
      <FullProductName ProductID="php74-gmp-7.4.33-1.47.2">php74-gmp-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-iconv-7.4.33-1.47.2">
      <FullProductName ProductID="php74-iconv-7.4.33-1.47.2">php74-iconv-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-intl-7.4.33-1.47.2">
      <FullProductName ProductID="php74-intl-7.4.33-1.47.2">php74-intl-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-json-7.4.33-1.47.2">
      <FullProductName ProductID="php74-json-7.4.33-1.47.2">php74-json-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-ldap-7.4.33-1.47.2">
      <FullProductName ProductID="php74-ldap-7.4.33-1.47.2">php74-ldap-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-mbstring-7.4.33-1.47.2">
      <FullProductName ProductID="php74-mbstring-7.4.33-1.47.2">php74-mbstring-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-mysql-7.4.33-1.47.2">
      <FullProductName ProductID="php74-mysql-7.4.33-1.47.2">php74-mysql-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-odbc-7.4.33-1.47.2">
      <FullProductName ProductID="php74-odbc-7.4.33-1.47.2">php74-odbc-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-opcache-7.4.33-1.47.2">
      <FullProductName ProductID="php74-opcache-7.4.33-1.47.2">php74-opcache-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-openssl-7.4.33-1.47.2">
      <FullProductName ProductID="php74-openssl-7.4.33-1.47.2">php74-openssl-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-pcntl-7.4.33-1.47.2">
      <FullProductName ProductID="php74-pcntl-7.4.33-1.47.2">php74-pcntl-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-pdo-7.4.33-1.47.2">
      <FullProductName ProductID="php74-pdo-7.4.33-1.47.2">php74-pdo-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-pgsql-7.4.33-1.47.2">
      <FullProductName ProductID="php74-pgsql-7.4.33-1.47.2">php74-pgsql-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-phar-7.4.33-1.47.2">
      <FullProductName ProductID="php74-phar-7.4.33-1.47.2">php74-phar-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-posix-7.4.33-1.47.2">
      <FullProductName ProductID="php74-posix-7.4.33-1.47.2">php74-posix-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-readline-7.4.33-1.47.2">
      <FullProductName ProductID="php74-readline-7.4.33-1.47.2">php74-readline-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-shmop-7.4.33-1.47.2">
      <FullProductName ProductID="php74-shmop-7.4.33-1.47.2">php74-shmop-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-snmp-7.4.33-1.47.2">
      <FullProductName ProductID="php74-snmp-7.4.33-1.47.2">php74-snmp-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-soap-7.4.33-1.47.2">
      <FullProductName ProductID="php74-soap-7.4.33-1.47.2">php74-soap-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-sockets-7.4.33-1.47.2">
      <FullProductName ProductID="php74-sockets-7.4.33-1.47.2">php74-sockets-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-sodium-7.4.33-1.47.2">
      <FullProductName ProductID="php74-sodium-7.4.33-1.47.2">php74-sodium-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-sqlite-7.4.33-1.47.2">
      <FullProductName ProductID="php74-sqlite-7.4.33-1.47.2">php74-sqlite-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-sysvmsg-7.4.33-1.47.2">
      <FullProductName ProductID="php74-sysvmsg-7.4.33-1.47.2">php74-sysvmsg-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-sysvsem-7.4.33-1.47.2">
      <FullProductName ProductID="php74-sysvsem-7.4.33-1.47.2">php74-sysvsem-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-sysvshm-7.4.33-1.47.2">
      <FullProductName ProductID="php74-sysvshm-7.4.33-1.47.2">php74-sysvshm-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-test-7.4.33-1.47.2">
      <FullProductName ProductID="php74-test-7.4.33-1.47.2">php74-test-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-tidy-7.4.33-1.47.2">
      <FullProductName ProductID="php74-tidy-7.4.33-1.47.2">php74-tidy-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-tokenizer-7.4.33-1.47.2">
      <FullProductName ProductID="php74-tokenizer-7.4.33-1.47.2">php74-tokenizer-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-xmlreader-7.4.33-1.47.2">
      <FullProductName ProductID="php74-xmlreader-7.4.33-1.47.2">php74-xmlreader-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-xmlrpc-7.4.33-1.47.2">
      <FullProductName ProductID="php74-xmlrpc-7.4.33-1.47.2">php74-xmlrpc-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-xmlwriter-7.4.33-1.47.2">
      <FullProductName ProductID="php74-xmlwriter-7.4.33-1.47.2">php74-xmlwriter-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-xsl-7.4.33-1.47.2">
      <FullProductName ProductID="php74-xsl-7.4.33-1.47.2">php74-xsl-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-zip-7.4.33-1.47.2">
      <FullProductName ProductID="php74-zip-7.4.33-1.47.2">php74-zip-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php74-zlib-7.4.33-1.47.2">
      <FullProductName ProductID="php74-zlib-7.4.33-1.47.2">php74-zlib-7.4.33-1.47.2</FullProductName>
    </Branch>
    <Relationship ProductReference="apache2-mod_php74-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2">apache2-mod_php74-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2">php74-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-bcmath-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2">php74-bcmath-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-bz2-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2">php74-bz2-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-calendar-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2">php74-calendar-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-ctype-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2">php74-ctype-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-curl-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2">php74-curl-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-dba-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2">php74-dba-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-dom-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2">php74-dom-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-enchant-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2">php74-enchant-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-exif-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2">php74-exif-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-fastcgi-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2">php74-fastcgi-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-fileinfo-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2">php74-fileinfo-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-fpm-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2">php74-fpm-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-ftp-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2">php74-ftp-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-gd-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2">php74-gd-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-gettext-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2">php74-gettext-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-gmp-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2">php74-gmp-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-iconv-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2">php74-iconv-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-intl-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2">php74-intl-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-json-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2">php74-json-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-ldap-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2">php74-ldap-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-mbstring-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2">php74-mbstring-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-mysql-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2">php74-mysql-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-odbc-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2">php74-odbc-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-opcache-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2">php74-opcache-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-openssl-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2">php74-openssl-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-pcntl-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2">php74-pcntl-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-pdo-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2">php74-pdo-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-pgsql-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2">php74-pgsql-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-phar-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2">php74-phar-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-posix-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2">php74-posix-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-readline-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2">php74-readline-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-shmop-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2">php74-shmop-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-snmp-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2">php74-snmp-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-soap-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2">php74-soap-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-sockets-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2">php74-sockets-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-sodium-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2">php74-sodium-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-sqlite-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2">php74-sqlite-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-sysvmsg-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2">php74-sysvmsg-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-sysvsem-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2">php74-sysvsem-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-sysvshm-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2">php74-sysvshm-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-tidy-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2">php74-tidy-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-tokenizer-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2">php74-tokenizer-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-xmlreader-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2">php74-xmlreader-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-xmlrpc-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2">php74-xmlrpc-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-xmlwriter-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2">php74-xmlwriter-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-xsl-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2">php74-xsl-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-zip-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2">php74-zip-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-zlib-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2">php74-zlib-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="php74-devel-7.4.33-1.47.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2">php74-devel-7.4.33-1.47.2 as a component of SUSE Linux Enterprise Software Development Kit 12 SP5</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.</Note>
    </Notes>
    <CVE>CVE-2017-8923</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-8923.html</URL>
        <Description>CVE-2017-8923</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1038980</URL>
        <Description>SUSE Bug 1038980</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.</Note>
    </Notes>
    <CVE>CVE-2020-7068</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.3</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-7068.html</URL>
        <Description>CVE-2020-7068</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1175203</URL>
        <Description>SUSE Bug 1175203</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1175223</URL>
        <Description>SUSE Bug 1175223</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.</Note>
    </Notes>
    <CVE>CVE-2020-7069</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-7069.html</URL>
        <Description>CVE-2020-7069</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177351</URL>
        <Description>SUSE Bug 1177351</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. See also CVE-2020-8184 for more information.</Note>
    </Notes>
    <CVE>CVE-2020-7070</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-7070.html</URL>
        <Description>CVE-2020-7070</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177352</URL>
        <Description>SUSE Bug 1177352</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL.</Note>
    </Notes>
    <CVE>CVE-2020-7071</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-7071.html</URL>
        <Description>CVE-2020-7071</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180706</URL>
        <Description>SUSE Bug 1180706</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182049</URL>
        <Description>SUSE Bug 1182049</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.</Note>
    </Notes>
    <CVE>CVE-2021-21702</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21702.html</URL>
        <Description>CVE-2021-21702</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182049</URL>
        <Description>SUSE Bug 1182049</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user.</Note>
    </Notes>
    <CVE>CVE-2021-21703</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21703.html</URL>
        <Description>CVE-2021-21703</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1192050</URL>
        <Description>SUSE Bug 1192050</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.</Note>
    </Notes>
    <CVE>CVE-2021-21704</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21704.html</URL>
        <Description>CVE-2021-21704</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1188035</URL>
        <Description>SUSE Bug 1188035</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.</Note>
    </Notes>
    <CVE>CVE-2021-21705</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21705.html</URL>
        <Description>CVE-2021-21705</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1188037</URL>
        <Description>SUSE Bug 1188037</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.</Note>
    </Notes>
    <CVE>CVE-2021-21706</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21706.html</URL>
        <Description>CVE-2021-21706</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1191314</URL>
        <Description>SUSE Bug 1191314</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.</Note>
    </Notes>
    <CVE>CVE-2021-21707</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21707.html</URL>
        <Description>CVE-2021-21707</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1193041</URL>
        <Description>SUSE Bug 1193041</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.</Note>
    </Notes>
    <CVE>CVE-2021-21708</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21708.html</URL>
        <Description>CVE-2021-21708</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196252</URL>
        <Description>SUSE Bug 1196252</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.</Note>
    </Notes>
    <CVE>CVE-2022-31625</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-31625.html</URL>
        <Description>CVE-2022-31625</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1200645</URL>
        <Description>SUSE Bug 1200645</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.</Note>
    </Notes>
    <CVE>CVE-2022-31626</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6</BaseScore>
        <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-31626.html</URL>
        <Description>CVE-2022-31626</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1200628</URL>
        <Description>SUSE Bug 1200628</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.</Note>
    </Notes>
    <CVE>CVE-2022-31628</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-31628.html</URL>
        <Description>CVE-2022-31628</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1203867</URL>
        <Description>SUSE Bug 1203867</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.</Note>
    </Notes>
    <CVE>CVE-2022-31629</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-31629.html</URL>
        <Description>CVE-2022-31629</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1203870</URL>
        <Description>SUSE Bug 1203870</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1222857</URL>
        <Description>SUSE Bug 1222857</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.  </Note>
    </Notes>
    <CVE>CVE-2022-31630</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-31630.html</URL>
        <Description>CVE-2022-31630</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1204979</URL>
        <Description>SUSE Bug 1204979</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.</Note>
    </Notes>
    <CVE>CVE-2022-37454</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bcmath-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-bz2-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-calendar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ctype-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-curl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dba-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-dom-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-enchant-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-exif-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fastcgi-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fileinfo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-fpm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ftp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gd-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gettext-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-gmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-iconv-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-intl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-json-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-ldap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mbstring-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-mysql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-odbc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-opcache-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-openssl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pcntl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pdo-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-pgsql-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-phar-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-posix-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-readline-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-shmop-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-snmp-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-soap-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sockets-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sodium-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sqlite-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvmsg-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvsem-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-sysvshm-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tidy-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-tokenizer-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlreader-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlrpc-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xmlwriter-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-xsl-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zip-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:php74-zlib-7.4.33-1.47.2</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:php74-devel-7.4.33-1.47.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2022/suse-su-20224068-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-37454.html</URL>
        <Description>CVE-2022-37454</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1204577</URL>
        <Description>SUSE Bug 1204577</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1204966</URL>
        <Description>SUSE Bug 1204966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1205836</URL>
        <Description>SUSE Bug 1205836</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
