Those CVEs were announced here: https://www.openwall.com/lists/oss-security/2024/06/07/1 Mageia 9 is also affected.
CVE: (none) => CVE-2024-4577, CVE-2024-5458, CVE-2024-5585Whiteboard: (none) => MGA9TOOSource RPM: (none) => php-8.3.8-1.mga10.src.rpmStatus comment: (none) => Fixed upstream in 8.3.8, 8.2.20 and 8.1.29
Severity: normal => critical
Assigning to PHP stack maintainers.
Assignee: bugsquad => php
Depends on: (none) => 33358
Depends on: (none) => 33359
CVE-2024-4577 is windows only, not affected: "...when using Apache and PHP-CGI on Windows..." CVE-2024-5458: affected (moderate) CVE-2024-5585: not affected: "...the user can supply arguments that would execute arbitrary commands in Windows shell..."
CC: (none) => mageia
Fixed by bug 33359 and bug 33358.
Resolution: (none) => FIXEDStatus: NEW => RESOLVED