<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Recommended update for php7</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2021:1570-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-12-10T17:06:23Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-12-10T17:06:23Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-12-10T17:06:23Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Recommended update for php7</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for php7 fixes the following issues:

- CVE-2021-21703: Fixed local privilege escalation via PHP-FPM (bsc#1192050).
- CVE-2021-21707: Fixed special character breaks path in xml parsing (bsc#1193041).

- Added patch to prevent memory access violation in php7 when running test suite (bsc#1175508)

This update was imported from the SUSE:SLE-15-SP2:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2021-1570</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RQSJP4Z6SALIQMUAEV267NSJB6EATBOB/</URL>
      <Description>E-Mail link for openSUSE-SU-2021:1570-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1175508</URL>
      <Description>SUSE Bug 1175508</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1192050</URL>
      <Description>SUSE Bug 1192050</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1193041</URL>
      <Description>SUSE Bug 1193041</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21703/</URL>
      <Description>SUSE CVE CVE-2021-21703 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21707/</URL>
      <Description>SUSE CVE CVE-2021-21707 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 15.2">
      <Branch Type="Product Name" Name="openSUSE Leap 15.2">
        <FullProductName ProductID="openSUSE Leap 15.2" CPE="cpe:/o:opensuse:leap:15.2">openSUSE Leap 15.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="apache2-mod_php7-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="apache2-mod_php7-7.4.6-lp152.2.21.1">apache2-mod_php7-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-7.4.6-lp152.2.21.1">php7-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-bcmath-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-bcmath-7.4.6-lp152.2.21.1">php7-bcmath-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-bz2-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-bz2-7.4.6-lp152.2.21.1">php7-bz2-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-calendar-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-calendar-7.4.6-lp152.2.21.1">php7-calendar-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ctype-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-ctype-7.4.6-lp152.2.21.1">php7-ctype-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-curl-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-curl-7.4.6-lp152.2.21.1">php7-curl-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-dba-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-dba-7.4.6-lp152.2.21.1">php7-dba-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-devel-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-devel-7.4.6-lp152.2.21.1">php7-devel-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-dom-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-dom-7.4.6-lp152.2.21.1">php7-dom-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-embed-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-embed-7.4.6-lp152.2.21.1">php7-embed-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-enchant-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-enchant-7.4.6-lp152.2.21.1">php7-enchant-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-exif-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-exif-7.4.6-lp152.2.21.1">php7-exif-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fastcgi-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-fastcgi-7.4.6-lp152.2.21.1">php7-fastcgi-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fileinfo-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-fileinfo-7.4.6-lp152.2.21.1">php7-fileinfo-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-firebird-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-firebird-7.4.6-lp152.2.21.1">php7-firebird-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-fpm-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-fpm-7.4.6-lp152.2.21.1">php7-fpm-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ftp-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-ftp-7.4.6-lp152.2.21.1">php7-ftp-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gd-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-gd-7.4.6-lp152.2.21.1">php7-gd-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gettext-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-gettext-7.4.6-lp152.2.21.1">php7-gettext-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-gmp-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-gmp-7.4.6-lp152.2.21.1">php7-gmp-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-iconv-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-iconv-7.4.6-lp152.2.21.1">php7-iconv-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-intl-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-intl-7.4.6-lp152.2.21.1">php7-intl-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-json-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-json-7.4.6-lp152.2.21.1">php7-json-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-ldap-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-ldap-7.4.6-lp152.2.21.1">php7-ldap-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mbstring-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-mbstring-7.4.6-lp152.2.21.1">php7-mbstring-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-mysql-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-mysql-7.4.6-lp152.2.21.1">php7-mysql-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-odbc-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-odbc-7.4.6-lp152.2.21.1">php7-odbc-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-opcache-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-opcache-7.4.6-lp152.2.21.1">php7-opcache-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-openssl-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-openssl-7.4.6-lp152.2.21.1">php7-openssl-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pcntl-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-pcntl-7.4.6-lp152.2.21.1">php7-pcntl-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pdo-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-pdo-7.4.6-lp152.2.21.1">php7-pdo-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-pgsql-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-pgsql-7.4.6-lp152.2.21.1">php7-pgsql-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-phar-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-phar-7.4.6-lp152.2.21.1">php7-phar-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-posix-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-posix-7.4.6-lp152.2.21.1">php7-posix-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-readline-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-readline-7.4.6-lp152.2.21.1">php7-readline-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-shmop-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-shmop-7.4.6-lp152.2.21.1">php7-shmop-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-snmp-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-snmp-7.4.6-lp152.2.21.1">php7-snmp-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-soap-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-soap-7.4.6-lp152.2.21.1">php7-soap-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sockets-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-sockets-7.4.6-lp152.2.21.1">php7-sockets-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sodium-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-sodium-7.4.6-lp152.2.21.1">php7-sodium-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sqlite-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-sqlite-7.4.6-lp152.2.21.1">php7-sqlite-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvmsg-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-sysvmsg-7.4.6-lp152.2.21.1">php7-sysvmsg-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvsem-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-sysvsem-7.4.6-lp152.2.21.1">php7-sysvsem-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-sysvshm-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-sysvshm-7.4.6-lp152.2.21.1">php7-sysvshm-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-test-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-test-7.4.6-lp152.2.21.1">php7-test-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-tidy-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-tidy-7.4.6-lp152.2.21.1">php7-tidy-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-tokenizer-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-tokenizer-7.4.6-lp152.2.21.1">php7-tokenizer-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlreader-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-xmlreader-7.4.6-lp152.2.21.1">php7-xmlreader-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlrpc-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-xmlrpc-7.4.6-lp152.2.21.1">php7-xmlrpc-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xmlwriter-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-xmlwriter-7.4.6-lp152.2.21.1">php7-xmlwriter-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-xsl-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-xsl-7.4.6-lp152.2.21.1">php7-xsl-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-zip-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-zip-7.4.6-lp152.2.21.1">php7-zip-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php7-zlib-7.4.6-lp152.2.21.1">
      <FullProductName ProductID="php7-zlib-7.4.6-lp152.2.21.1">php7-zlib-7.4.6-lp152.2.21.1</FullProductName>
    </Branch>
    <Relationship ProductReference="apache2-mod_php7-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:apache2-mod_php7-7.4.6-lp152.2.21.1">apache2-mod_php7-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-7.4.6-lp152.2.21.1">php7-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-bcmath-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-bcmath-7.4.6-lp152.2.21.1">php7-bcmath-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-bz2-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-bz2-7.4.6-lp152.2.21.1">php7-bz2-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-calendar-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-calendar-7.4.6-lp152.2.21.1">php7-calendar-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ctype-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-ctype-7.4.6-lp152.2.21.1">php7-ctype-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-curl-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-curl-7.4.6-lp152.2.21.1">php7-curl-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-dba-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-dba-7.4.6-lp152.2.21.1">php7-dba-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-devel-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-devel-7.4.6-lp152.2.21.1">php7-devel-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-dom-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-dom-7.4.6-lp152.2.21.1">php7-dom-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-embed-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-embed-7.4.6-lp152.2.21.1">php7-embed-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-enchant-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-enchant-7.4.6-lp152.2.21.1">php7-enchant-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-exif-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-exif-7.4.6-lp152.2.21.1">php7-exif-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fastcgi-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-fastcgi-7.4.6-lp152.2.21.1">php7-fastcgi-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fileinfo-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-fileinfo-7.4.6-lp152.2.21.1">php7-fileinfo-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-firebird-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-firebird-7.4.6-lp152.2.21.1">php7-firebird-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-fpm-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-fpm-7.4.6-lp152.2.21.1">php7-fpm-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ftp-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-ftp-7.4.6-lp152.2.21.1">php7-ftp-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gd-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-gd-7.4.6-lp152.2.21.1">php7-gd-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gettext-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-gettext-7.4.6-lp152.2.21.1">php7-gettext-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-gmp-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-gmp-7.4.6-lp152.2.21.1">php7-gmp-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-iconv-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-iconv-7.4.6-lp152.2.21.1">php7-iconv-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-intl-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-intl-7.4.6-lp152.2.21.1">php7-intl-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-json-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-json-7.4.6-lp152.2.21.1">php7-json-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-ldap-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-ldap-7.4.6-lp152.2.21.1">php7-ldap-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mbstring-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-mbstring-7.4.6-lp152.2.21.1">php7-mbstring-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-mysql-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-mysql-7.4.6-lp152.2.21.1">php7-mysql-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-odbc-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-odbc-7.4.6-lp152.2.21.1">php7-odbc-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-opcache-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-opcache-7.4.6-lp152.2.21.1">php7-opcache-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-openssl-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-openssl-7.4.6-lp152.2.21.1">php7-openssl-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pcntl-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-pcntl-7.4.6-lp152.2.21.1">php7-pcntl-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pdo-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-pdo-7.4.6-lp152.2.21.1">php7-pdo-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-pgsql-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-pgsql-7.4.6-lp152.2.21.1">php7-pgsql-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-phar-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-phar-7.4.6-lp152.2.21.1">php7-phar-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-posix-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-posix-7.4.6-lp152.2.21.1">php7-posix-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-readline-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-readline-7.4.6-lp152.2.21.1">php7-readline-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-shmop-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-shmop-7.4.6-lp152.2.21.1">php7-shmop-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-snmp-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-snmp-7.4.6-lp152.2.21.1">php7-snmp-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-soap-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-soap-7.4.6-lp152.2.21.1">php7-soap-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sockets-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-sockets-7.4.6-lp152.2.21.1">php7-sockets-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sodium-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-sodium-7.4.6-lp152.2.21.1">php7-sodium-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sqlite-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-sqlite-7.4.6-lp152.2.21.1">php7-sqlite-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvmsg-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-sysvmsg-7.4.6-lp152.2.21.1">php7-sysvmsg-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvsem-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-sysvsem-7.4.6-lp152.2.21.1">php7-sysvsem-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-sysvshm-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-sysvshm-7.4.6-lp152.2.21.1">php7-sysvshm-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-test-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-test-7.4.6-lp152.2.21.1">php7-test-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-tidy-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-tidy-7.4.6-lp152.2.21.1">php7-tidy-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-tokenizer-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-tokenizer-7.4.6-lp152.2.21.1">php7-tokenizer-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlreader-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-xmlreader-7.4.6-lp152.2.21.1">php7-xmlreader-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlrpc-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-xmlrpc-7.4.6-lp152.2.21.1">php7-xmlrpc-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xmlwriter-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-xmlwriter-7.4.6-lp152.2.21.1">php7-xmlwriter-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-xsl-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-xsl-7.4.6-lp152.2.21.1">php7-xsl-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-zip-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-zip-7.4.6-lp152.2.21.1">php7-zip-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="php7-zlib-7.4.6-lp152.2.21.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:php7-zlib-7.4.6-lp152.2.21.1">php7-zlib-7.4.6-lp152.2.21.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user.</Note>
    </Notes>
    <CVE>CVE-2021-21703</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.2:apache2-mod_php7-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-bcmath-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-bz2-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-calendar-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-ctype-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-curl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-dba-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-devel-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-dom-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-embed-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-enchant-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-exif-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-fastcgi-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-fileinfo-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-firebird-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-fpm-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-ftp-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-gd-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-gettext-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-gmp-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-iconv-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-intl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-json-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-ldap-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-mbstring-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-mysql-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-odbc-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-opcache-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-openssl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-pcntl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-pdo-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-pgsql-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-phar-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-posix-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-readline-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-shmop-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-snmp-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-soap-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sockets-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sodium-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sqlite-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sysvmsg-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sysvsem-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sysvshm-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-test-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-tidy-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-tokenizer-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-xmlreader-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-xmlrpc-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-xmlwriter-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-xsl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-zip-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-zlib-7.4.6-lp152.2.21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RQSJP4Z6SALIQMUAEV267NSJB6EATBOB/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21703.html</URL>
        <Description>CVE-2021-21703</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1192050</URL>
        <Description>SUSE Bug 1192050</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.</Note>
    </Notes>
    <CVE>CVE-2021-21707</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.2:apache2-mod_php7-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-bcmath-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-bz2-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-calendar-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-ctype-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-curl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-dba-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-devel-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-dom-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-embed-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-enchant-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-exif-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-fastcgi-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-fileinfo-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-firebird-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-fpm-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-ftp-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-gd-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-gettext-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-gmp-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-iconv-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-intl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-json-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-ldap-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-mbstring-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-mysql-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-odbc-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-opcache-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-openssl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-pcntl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-pdo-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-pgsql-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-phar-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-posix-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-readline-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-shmop-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-snmp-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-soap-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sockets-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sodium-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sqlite-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sysvmsg-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sysvsem-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-sysvshm-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-test-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-tidy-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-tokenizer-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-xmlreader-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-xmlrpc-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-xmlwriter-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-xsl-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-zip-7.4.6-lp152.2.21.1</ProductID>
        <ProductID>openSUSE Leap 15.2:php7-zlib-7.4.6-lp152.2.21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RQSJP4Z6SALIQMUAEV267NSJB6EATBOB/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21707.html</URL>
        <Description>CVE-2021-21707</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1193041</URL>
        <Description>SUSE Bug 1193041</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
