Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 29: Essential Buffer Overflow Security Updates for PHP 7.2.21

fedora
Calendar Grey August 7, 2019
Dist Fedora Esm H88
In Fedora 29, the PHP scripting language received an upgrade aimed at addressing various issues such as serious memory leaks and critical buffer overflows.
**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime)

Summary

PHP is an HTML-embedded scripting language. PHP attempts to make it

easy for developers to write dynamically generated web pages. PHP also

offers built-in database integration for several commercial and

non-commercial database management systems, so writing a

database-enabled webpage with PHP is fairly simple. The most common

use of PHP coding is probably as a replacement for CGI scripts.

The php package contains the module (often referred to as mod_php)

which adds support for the PHP language to Apache HTTP Server.

**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044

(discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug

php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042)

(Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail).

(CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows

wrong mime-type for .tga file). (Joshua Westerheide) **FTP:** * Fixed bug

php#77124 (FTP with SSL memory leak). (Nikita) **Libxml:** * Fixed bug

php#78279 (libxml_disable_entity_loader settings is shared between requests

(cgi-fcgi)). (Nikita) **LiteSpeed:** * Updated to LiteSpeed SAPI V7.4.3

(increased response header count limit from 100 to 1000, added crash handler to

cleanly shutdown PHP request, added CloudLinux mod_lsapi mode). (George Wang) *

Fixed bug php#76058 (After "POST data can't be buffered", using php://input

makes huge tmp files). (George Wang) **Openssl:** * Fixed bug php#78231

(Segmentation fault upon stream_socket_accept of exported socket-to-stream).

(Nikita) **OPcache:** * Fixed bug php#78189 (file cache strips last character

of uname hash). (cmb) * Fixed bug php#78202 (Opcache stats for cache hits are

capped at 32bit NUM). (cmb) * Fixed bug php#78291 (opcache_get_configuration

doesn't list all directives). (Andrew Collington) **Phar:** * Fixed bug

php#77919 (Potential UAF in Phar RSHUTDOWN). (cmb) **Phpdbg:** * Fixed bug

php#78297 (Include unexistent file memory leak). (Nikita) **PDO_Sqlite:** *

Fixed bug php#78192 (SegFault when reuse statement after schema has changed).

(Vincent Quatrevieux) **Standard:** * Fixed bug php#78241 (touch() does not

handle dates after 2038 in PHP 64-bit). (cmb) * Fixed bug php#78269

(password_hash uses weak options for argon2). (Remi) **XMLRPC:** * Fixed bug

php#78173 (XML-RPC mutates immutable objects during encoding). (Asher Baker)

* Tue Jul 30 2019 Remi Collet - 7.2.21-1

- Update to 7.2.21 - https://www.php.net/releases/7_2_21.php

* Tue Jul 2 2019 Remi Collet - 7.2.20-1

- Update to 7.2.20 - https://www.php.net/releases/7_2_20.php

* Wed May 29 2019 Remi Collet - 7.2.19-2

- Update to 7.2.19 - https://www.php.net/releases/7_2_19.php

* Tue Apr 30 2019 Remi Collet - 7.2.18-1

- Update to 7.2.18 - https://www.php.net/releases/7_2_18.php

* Wed Apr 3 2019 Remi Collet - 7.2.17-1

- Update to 7.2.17 - https://www.php.net/releases/7_2_17.php

* Wed Mar 6 2019 Remi Collet - 7.2.16-1

- Update to 7.2.16 - https://www.php.net/releases/7_2_16.php

- add upstream patch for OpenSSL 1.1.1b

- adapt systzdata patch (v17)

* Wed Feb 6 2019 Remi Collet - 7.2.15-1

- Update to 7.2.15 - https://www.php.net/releases/7_2_15.php

* Tue Jan 8 2019 Remi Collet - 7.2.14-1

- Update to 7.2.14 - https://www.php.net/releases/7_2_14.php

* Tue Dec 18 2018 Remi Collet - 7.2.14~RC1-1

- update to 7.2.14RC1

* Sat Dec 8 2018 Remi Collet - 7.2.13-2

- Fix null pointer dereference in imap_mail CVE-2018-19935

* Wed Dec 5 2018 Remi Collet - 7.2.13-1

- Update to 7.2.13 - https://www.php.net/releases/7_2_13.php

* Wed Nov 21 2018 Remi Collet - 7.2.13-0.1.RC1

- update to 7.2.13RC1

* Tue Nov 6 2018 Remi Collet - 7.2.12-1

- Update to 7.2.12 - https://www.php.net/releases/7_2_12.php

* Fri Nov 2 2018 Remi Collet - 7.2.12-0.1.RC1

- rebuild

* Tue Oct 23 2018 Remi Collet - 7.2.12~RC1-1

- update to 7.2.12RC1

* Wed Oct 10 2018 Remi Collet - 7.2.11-1

- Update to 7.2.11 - https://www.php.net/releases/7_2_11.php

su -c 'dnf upgrade --advisory FEDORA-2019-f07db8f031' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 29
Version: 7.2.21
Release: 1.fc29
Summary: PHP scripting language for creating dynamic web sites

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here