-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 SUMMARY cPanel, L.L.C. has updated packages for EasyApache 4 with PHP versions 8.3.12, 8.2.24, and 8.1.30. This release addresses vulnerabilities related to CVE-2024-9026, CVE-2024-8925, CVE-2024-8926, and CVE-2024-8927. We strongly encourage all PHP 8.1 users update to version 8.1.30, all PHP 8.2 users update to version 8.2.24, and all PHP 8.3 users to update to version 8.3.12. AFFECTED VERSIONS All versions of PHP 8.1 through version 8.1.29. All versions of PHP 8.2 through 8.2.23. All versions of PHP 8.3 through 8.3.11. SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2024-9026 - MEDIUM PHP 8.1.30 Fixed vulnerability related to CVE-2024-9026 PHP 8.2.24 Fixed vulnerability related to CVE-2024-9026 PHP 8.3.12 Fixed vulnerability related to CVE-2024-9026 CVE-2024-8925 - MEDIUM PHP 8.1.30 Fixed vulnerability related to CVE-2024-8925 PHP 8.2.24 Fixed vulnerability related to CVE-2024-8925 PHP 8.3.12 Fixed vulnerability related to CVE-2024-8925 CVE-2024-8926 - MEDIUM PHP 8.1.30 Fixed vulnerability related to CVE-2024-8926 PHP 8.2.24 Fixed vulnerability related to CVE-2024-8926 PHP 8.3.12 Fixed vulnerability related to CVE-2024-8926 CVE-2024-8927 - MEDIUM PHP 8.1.30 Fixed vulnerability related to CVE-2024-8927 PHP 8.2.24 Fixed vulnerability related to CVE-2024-8927 PHP 8.3.12 Fixed vulnerability related to CVE-2024-8927 SOLUTION cPanel, L.L.C. has released updated packages for EasyApache 4 on OCTOBER 2, 2024, with PHP versions 8.3.12, 8.2.24, and 8.1.30. Unless you have enabled automatic package updates in your cron, update your system with either your package manager or WHM's Run System Update interface. REFERENCES https://www.cve.org/CVERecord?id=CVE-2024-9026 https://www.cve.org/CVERecord?id=CVE-2024-8925 https://www.cve.org/CVERecord?id=CVE-2024-8926 https://www.cve.org/CVERecord?id=CVE-2024-8927 https://www.php.net/ChangeLog-8.php#8.1.30 https://www.php.net/ChangeLog-8.php#8.2.24 https://www.php.net/ChangeLog-8.php#8.3.12 -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEtnCbTMb0IHf2mEGRlSG+3KvZTd8FAmb9wIsACgkQlSG+3KvZ Td+fCg//SK7yC3YbvZxEuA6a3IyEJpIqr+t05AIW13G4aCFJpNXM4+RskWQwzfwp ac6VDar0j7Z35miARuBgvxxceTyA7kf7ZAfjPdvwvkfSV+3hGo6270udfl8HPvdK 3B4MGbF9ftrQMvbj4V18gRU2p/2RXbXXOxfputrSVHB9Jb0zEIF7ulZeirIWJM7z mmClYlrfIJMk0NdLQnoHjr7Ub3el6b2DzePOOKaGmQIeDwa54wrfbxNxG1BSezgF aylizB2Mb2PncR26MUe1OAcY5ZUBkjFuaVyi6Ih+tcNO3n58U6XiENcjSEu1rLfx /o2nIIm0u6sjgCT0eOEbX/oXDzvVVg+bKAu3Ux1e/DhUhnAAiHarqdkdfnORYbaL pv57ut6QSL3YqYtnDQRLuLWCeSkIKh8MexSQZptgcPP8rWYaQg6CCmiU2TLHOZcZ F4k5Q+QB+oaZNtHo6V/IcNIyph9g4sFkWsw2AQzJDXUI79ShRsflgp5Bkr165m7D qDHTORYwQMVRsKef521l59xsDLz5xr5xi9xmzQ1gjkV/avvzQCuEF8clH58N3cUQ PUx0gYrPHR77IJSBm5kmXZB0cUe4kVpXFyhMewUnSnsIeL+EQkbMrxcgwKZIEoeA fokvTpdTCSOmRx5GWgnZsioZjaz7P50XN8+E8kMgDt+0ygUw/8M= =toIP -----END PGP SIGNATURE-----