ArchLinux: 202101-9: php: insufficient validation
Summary
A security issue was found in the php_url_parse_ex() function in PHP, which leads to FILTER_VALIDATE_URL accepting URLs with invalid userinfo. It is fixed in versions 8.0.1, 7.4.14 and 7.3.26.
Resolution
Upgrade to 7.4.14-1.
# pacman -Syu "php>=7.4.14-1"
The problem has been fixed upstream in version 7.4.14.
References
https://bugs.archlinux.org/task/69242 https://bugs.php.net/bug.php?id=77423 ;a=commitdiff;h=b7f837381ef642d7fb369bfd0069e7525d4c22ea ;a=commitdiff;h=5346d0ae69f290c7704a39cd10a574a2d661f05a ;a=commitdiff;h=d4f5aed22193106271510efd643ba8f349b7d85f https://security.archlinux.org/CVE-2020-7071
Workaround
None.