<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">php8-8.3.12-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:14376-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-09-29T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-09-29T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-09-29T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">php8-8.3.12-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the php8-8.3.12-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-14376</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RM3WP4ENMVRYGM7IU7L7DTX3KTTN5UHE/</URL>
      <Description>E-Mail link for openSUSE-SU-2024:14376-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-4577/</URL>
      <Description>SUSE CVE CVE-2024-4577 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-8925/</URL>
      <Description>SUSE CVE CVE-2024-8925 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-8927/</URL>
      <Description>SUSE CVE CVE-2024-8927 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-9026/</URL>
      <Description>SUSE CVE CVE-2024-9026 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="php8-8.3.12-1.1">
      <FullProductName ProductID="php8-8.3.12-1.1">php8-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-bcmath-8.3.12-1.1">
      <FullProductName ProductID="php8-bcmath-8.3.12-1.1">php8-bcmath-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-bz2-8.3.12-1.1">
      <FullProductName ProductID="php8-bz2-8.3.12-1.1">php8-bz2-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-calendar-8.3.12-1.1">
      <FullProductName ProductID="php8-calendar-8.3.12-1.1">php8-calendar-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-cli-8.3.12-1.1">
      <FullProductName ProductID="php8-cli-8.3.12-1.1">php8-cli-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-ctype-8.3.12-1.1">
      <FullProductName ProductID="php8-ctype-8.3.12-1.1">php8-ctype-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-curl-8.3.12-1.1">
      <FullProductName ProductID="php8-curl-8.3.12-1.1">php8-curl-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-dba-8.3.12-1.1">
      <FullProductName ProductID="php8-dba-8.3.12-1.1">php8-dba-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-devel-8.3.12-1.1">
      <FullProductName ProductID="php8-devel-8.3.12-1.1">php8-devel-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-dom-8.3.12-1.1">
      <FullProductName ProductID="php8-dom-8.3.12-1.1">php8-dom-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-enchant-8.3.12-1.1">
      <FullProductName ProductID="php8-enchant-8.3.12-1.1">php8-enchant-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-exif-8.3.12-1.1">
      <FullProductName ProductID="php8-exif-8.3.12-1.1">php8-exif-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-ffi-8.3.12-1.1">
      <FullProductName ProductID="php8-ffi-8.3.12-1.1">php8-ffi-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-fileinfo-8.3.12-1.1">
      <FullProductName ProductID="php8-fileinfo-8.3.12-1.1">php8-fileinfo-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-ftp-8.3.12-1.1">
      <FullProductName ProductID="php8-ftp-8.3.12-1.1">php8-ftp-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-gd-8.3.12-1.1">
      <FullProductName ProductID="php8-gd-8.3.12-1.1">php8-gd-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-gettext-8.3.12-1.1">
      <FullProductName ProductID="php8-gettext-8.3.12-1.1">php8-gettext-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-gmp-8.3.12-1.1">
      <FullProductName ProductID="php8-gmp-8.3.12-1.1">php8-gmp-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-iconv-8.3.12-1.1">
      <FullProductName ProductID="php8-iconv-8.3.12-1.1">php8-iconv-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-intl-8.3.12-1.1">
      <FullProductName ProductID="php8-intl-8.3.12-1.1">php8-intl-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-ldap-8.3.12-1.1">
      <FullProductName ProductID="php8-ldap-8.3.12-1.1">php8-ldap-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-mbstring-8.3.12-1.1">
      <FullProductName ProductID="php8-mbstring-8.3.12-1.1">php8-mbstring-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-mysql-8.3.12-1.1">
      <FullProductName ProductID="php8-mysql-8.3.12-1.1">php8-mysql-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-odbc-8.3.12-1.1">
      <FullProductName ProductID="php8-odbc-8.3.12-1.1">php8-odbc-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-opcache-8.3.12-1.1">
      <FullProductName ProductID="php8-opcache-8.3.12-1.1">php8-opcache-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-openssl-8.3.12-1.1">
      <FullProductName ProductID="php8-openssl-8.3.12-1.1">php8-openssl-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-pcntl-8.3.12-1.1">
      <FullProductName ProductID="php8-pcntl-8.3.12-1.1">php8-pcntl-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-pdo-8.3.12-1.1">
      <FullProductName ProductID="php8-pdo-8.3.12-1.1">php8-pdo-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-pgsql-8.3.12-1.1">
      <FullProductName ProductID="php8-pgsql-8.3.12-1.1">php8-pgsql-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-phar-8.3.12-1.1">
      <FullProductName ProductID="php8-phar-8.3.12-1.1">php8-phar-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-posix-8.3.12-1.1">
      <FullProductName ProductID="php8-posix-8.3.12-1.1">php8-posix-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-readline-8.3.12-1.1">
      <FullProductName ProductID="php8-readline-8.3.12-1.1">php8-readline-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-shmop-8.3.12-1.1">
      <FullProductName ProductID="php8-shmop-8.3.12-1.1">php8-shmop-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-snmp-8.3.12-1.1">
      <FullProductName ProductID="php8-snmp-8.3.12-1.1">php8-snmp-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-soap-8.3.12-1.1">
      <FullProductName ProductID="php8-soap-8.3.12-1.1">php8-soap-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sockets-8.3.12-1.1">
      <FullProductName ProductID="php8-sockets-8.3.12-1.1">php8-sockets-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sodium-8.3.12-1.1">
      <FullProductName ProductID="php8-sodium-8.3.12-1.1">php8-sodium-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sqlite-8.3.12-1.1">
      <FullProductName ProductID="php8-sqlite-8.3.12-1.1">php8-sqlite-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sysvmsg-8.3.12-1.1">
      <FullProductName ProductID="php8-sysvmsg-8.3.12-1.1">php8-sysvmsg-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sysvsem-8.3.12-1.1">
      <FullProductName ProductID="php8-sysvsem-8.3.12-1.1">php8-sysvsem-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sysvshm-8.3.12-1.1">
      <FullProductName ProductID="php8-sysvshm-8.3.12-1.1">php8-sysvshm-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-tidy-8.3.12-1.1">
      <FullProductName ProductID="php8-tidy-8.3.12-1.1">php8-tidy-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-tokenizer-8.3.12-1.1">
      <FullProductName ProductID="php8-tokenizer-8.3.12-1.1">php8-tokenizer-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-xmlreader-8.3.12-1.1">
      <FullProductName ProductID="php8-xmlreader-8.3.12-1.1">php8-xmlreader-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-xmlwriter-8.3.12-1.1">
      <FullProductName ProductID="php8-xmlwriter-8.3.12-1.1">php8-xmlwriter-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-xsl-8.3.12-1.1">
      <FullProductName ProductID="php8-xsl-8.3.12-1.1">php8-xsl-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-zip-8.3.12-1.1">
      <FullProductName ProductID="php8-zip-8.3.12-1.1">php8-zip-8.3.12-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-zlib-8.3.12-1.1">
      <FullProductName ProductID="php8-zlib-8.3.12-1.1">php8-zlib-8.3.12-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="php8-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-8.3.12-1.1">php8-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-bcmath-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-bcmath-8.3.12-1.1">php8-bcmath-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-bz2-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-bz2-8.3.12-1.1">php8-bz2-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-calendar-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-calendar-8.3.12-1.1">php8-calendar-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-cli-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-cli-8.3.12-1.1">php8-cli-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-ctype-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-ctype-8.3.12-1.1">php8-ctype-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-curl-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-curl-8.3.12-1.1">php8-curl-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-dba-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-dba-8.3.12-1.1">php8-dba-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-devel-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-devel-8.3.12-1.1">php8-devel-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-dom-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-dom-8.3.12-1.1">php8-dom-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-enchant-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-enchant-8.3.12-1.1">php8-enchant-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-exif-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-exif-8.3.12-1.1">php8-exif-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-ffi-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-ffi-8.3.12-1.1">php8-ffi-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-fileinfo-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-fileinfo-8.3.12-1.1">php8-fileinfo-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-ftp-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-ftp-8.3.12-1.1">php8-ftp-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-gd-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-gd-8.3.12-1.1">php8-gd-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-gettext-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-gettext-8.3.12-1.1">php8-gettext-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-gmp-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-gmp-8.3.12-1.1">php8-gmp-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-iconv-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-iconv-8.3.12-1.1">php8-iconv-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-intl-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-intl-8.3.12-1.1">php8-intl-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-ldap-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-ldap-8.3.12-1.1">php8-ldap-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-mbstring-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-mbstring-8.3.12-1.1">php8-mbstring-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-mysql-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-mysql-8.3.12-1.1">php8-mysql-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-odbc-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-odbc-8.3.12-1.1">php8-odbc-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-opcache-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-opcache-8.3.12-1.1">php8-opcache-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-openssl-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-openssl-8.3.12-1.1">php8-openssl-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-pcntl-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-pcntl-8.3.12-1.1">php8-pcntl-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-pdo-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-pdo-8.3.12-1.1">php8-pdo-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-pgsql-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-pgsql-8.3.12-1.1">php8-pgsql-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-phar-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-phar-8.3.12-1.1">php8-phar-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-posix-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-posix-8.3.12-1.1">php8-posix-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-readline-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-readline-8.3.12-1.1">php8-readline-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-shmop-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-shmop-8.3.12-1.1">php8-shmop-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-snmp-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-snmp-8.3.12-1.1">php8-snmp-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-soap-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-soap-8.3.12-1.1">php8-soap-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sockets-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sockets-8.3.12-1.1">php8-sockets-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sodium-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sodium-8.3.12-1.1">php8-sodium-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sqlite-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sqlite-8.3.12-1.1">php8-sqlite-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sysvmsg-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sysvmsg-8.3.12-1.1">php8-sysvmsg-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sysvsem-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sysvsem-8.3.12-1.1">php8-sysvsem-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sysvshm-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sysvshm-8.3.12-1.1">php8-sysvshm-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-tidy-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-tidy-8.3.12-1.1">php8-tidy-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-tokenizer-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-tokenizer-8.3.12-1.1">php8-tokenizer-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-xmlreader-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-xmlreader-8.3.12-1.1">php8-xmlreader-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-xmlwriter-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-xmlwriter-8.3.12-1.1">php8-xmlwriter-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-xsl-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-xsl-8.3.12-1.1">php8-xsl-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-zip-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-zip-8.3.12-1.1">php8-zip-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-zlib-8.3.12-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-zlib-8.3.12-1.1">php8-zlib-8.3.12-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions  8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to  Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.</Note>
    </Notes>
    <CVE>CVE-2024-4577</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ffi-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.3.12-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RM3WP4ENMVRYGM7IU7L7DTX3KTTN5UHE/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-4577.html</URL>
        <Description>CVE-2024-4577</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226072</URL>
        <Description>SUSE Bug 1226072</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226073</URL>
        <Description>SUSE Bug 1226073</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226074</URL>
        <Description>SUSE Bug 1226074</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions  8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.</Note>
    </Notes>
    <CVE>CVE-2024-8925</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ffi-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.3.12-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RM3WP4ENMVRYGM7IU7L7DTX3KTTN5UHE/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-8925.html</URL>
        <Description>CVE-2024-8925</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231360</URL>
        <Description>SUSE Bug 1231360</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12,  HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to  cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.</Note>
    </Notes>
    <CVE>CVE-2024-8927</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ffi-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.3.12-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RM3WP4ENMVRYGM7IU7L7DTX3KTTN5UHE/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-8927.html</URL>
        <Description>CVE-2024-8927</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231358</URL>
        <Description>SUSE Bug 1231358</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is  configured to catch workers output through catch_workers_output = yes,  it may be possible to pollute the final log or  remove up to 4 characters from the log messages by manipulating log message content. Additionally, if  PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.</Note>
    </Notes>
    <CVE>CVE-2024-9026</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ffi-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.3.12-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.3.12-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RM3WP4ENMVRYGM7IU7L7DTX3KTTN5UHE/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-9026.html</URL>
        <Description>CVE-2024-9026</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231382</URL>
        <Description>SUSE Bug 1231382</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
