Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Fedora 31: FEDORA-2019-a54a622670 Critical: PHP Multiple Issues

fedora
Calendar Grey January 4, 2020
Scroller Fedora
PHP 7.4.1 for Fedora 32 addresses key vulnerabilities such as memory leaks and several errata impacting essential operations.
**PHP version 7.3.13** (18 Dec 2019) **Bcmath:** * Fixed bug php#78878 (Buffer underflow in bc_shift_addsub)

Summary

PHP is an HTML-embedded scripting language. PHP attempts to make it

easy for developers to write dynamically generated web pages. PHP also

offers built-in database integration for several commercial and

non-commercial database management systems, so writing a

database-enabled webpage with PHP is fairly simple. The most common

use of PHP coding is probably as a replacement for CGI scripts.

The php package contains the module (often referred to as mod_php)

which adds support for the PHP language to Apache HTTP Server.

**PHP version 7.3.13** (18 Dec 2019) **Bcmath:** * Fixed bug php#78878 (Buffer

underflow in bc_shift_addsub). (**CVE-2019-11046**). (cmb) **Core:** * Fixed

bug php#78862 (link() silently truncates after a null byte on Windows).

(**CVE-2019-11044**). (cmb) * Fixed bug php#78863 (DirectoryIterator class

silently truncates after a null byte). (**CVE-2019-11045**). (cmb) * Fixed bug

php#78943 (mail() may release string with refcount==1 twice).

(**CVE-2019-11049**). (cmb) * Fixed bug php#78787 (Segfault with trait

overriding inherited private shadow property). (Nikita) * Fixed bug php#78868

(Calling __autoload() with incorrect EG(fake_scope) value). (Antony Dovgal,

Dmitry) * Fixed bug php#78296 (is_file fails to detect file). (cmb) **EXIF:**

* Fixed bug php#78793 (Use-after-free in exif parsing under memory sanitizer).

(**CVE-2019-11050**). (Nikita) * Fixed bug php#78910 (Heap-buffer-overflow READ

in exif). (**CVE-2019-11047**). (Nikita) **GD:** * Fixed bug php#78849 (GD

build broken with -D SIGNED_COMPARE_SLOW). (cmb) **MBString:** * Upgraded

bundled Oniguruma to 6.9.4. (cmb) **OPcache:** * Fixed potential ASLR related

invalid opline handler issues. (cmb) * Fixed $x = (bool)$x; with opcache (should

emit undeclared variable notice). (Tyson Andre) **PCRE:** * Fixed bug

php#78853 (preg_match() may return integer > 1). (cmb) **Standard:** * Fixed

bug php#78759 (array_search in $GLOBALS). (Nikita) * Fixed bug php#77638

(var_export'ing certain class instances segfaults). (cmb) * Fixed bug php#78840

(imploding $GLOBALS crashes). (cmb) * Fixed bug php#78833 (Integer overflow in

pack causes out-of-bound access). (cmb) * Fixed bug php#78814 (strip_tags allows

/ in tag name => whitelist bypass). (cmb)

* Tue Dec 17 2019 Remi Collet - 7.3.13-1

- Update to 7.3.13 - https://www.php.net/releases/7_3_13.php

* Tue Dec 3 2019 Remi Collet - 7.3.13~RC1-1

- update to 7.3.13RC1

* Tue Nov 19 2019 Remi Collet - 7.3.12-1

- Update to 7.3.12 - https://www.php.net/releases/7_3_12.php

* Wed Nov 6 2019 Remi Collet - 7.3.12~RC1-1

- update to 7.3.12RC1

* Tue Oct 22 2019 Remi Collet - 7.3.11-1

- Update to 7.3.11 - https://www.php.net/releases/7_3_11.php

su -c 'dnf upgrade --advisory FEDORA-2019-a54a622670' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 7.3.13
Release: 1.fc31
Summary: PHP scripting language for creating dynamic web sites

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.