Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Fedora 33: 2021-172c8bd11d Moderate: SSRF Bypass and Performance Issues

fedora
Calendar Grey July 7, 2021
Dist Fedora Esm H88
Updating to PHP 7.4.21 addresses critical issues such as SSRF and buffer overflow vulnerabilities, alongside best practice suggestions.
**PHP version 7.4.21** (01 Jul 2021) **Core:** * Fixed bug php#81068 (Double free in realpath_cache_clean())

Summary

PHP is an HTML-embedded scripting language. PHP attempts to make it

easy for developers to write dynamically generated web pages. PHP also

offers built-in database integration for several commercial and

non-commercial database management systems, so writing a

database-enabled webpage with PHP is fairly simple. The most common

use of PHP coding is probably as a replacement for CGI scripts.

**PHP version 7.4.21** (01 Jul 2021) **Core:** * Fixed bug php#81068 (Double

free in realpath_cache_clean()). (Dimitry Andric) * Fixed bug php#76359

(open_basedir bypass through adding ".."). (cmb) * Fixed bug php#81090 (Typed

property performance degradation with .= operator). (Nikita) * Fixed bug

php#81070 (Integer underflow in memory limit comparison). (Peter van Dommelen) *

Fixed bug php#81122 (SSRF bypass in FILTER_VALIDATE_URL). (**CVE-2021-21705**)

(cmb) **Bzip2:** * Fixed bug php#81092 (fflush before stream_filter_remove

corrupts stream). (cmb) **OpenSSL:** * Fixed bug php#76694 (native Windows

cert verification uses CN as sever name). (cmb) **PDO_Firebird:** * Fixed bug

php#76448 (Stack buffer overflow in firebird_info_cb). (**CVE-2021-21704**)

(cmb) * Fixed bug php#76449 (SIGSEGV in firebird_handle_doer).

(**CVE-2021-21704**) (cmb) * Fixed bug php#76450 (SIGSEGV in

firebird_stmt_execute). (**CVE-2021-21704**) (cmb) * Fixed bug php#76452 (Crash

while parsing blob data in firebird_fetch_blob). (**CVE-2021-21704**) (cmb)

**Standard:** * Fixed bug php#81048 (phpinfo(INFO_VARIABLES) "Array to string

conversion"). (cmb)

* Tue Jun 29 2021 Remi Collet - 7.4.21-1

- Update to 7.4.21 - https://www.php.net/releases/7_4_21.php

[ 1 ] Bug #1978755 - CVE-2021-21705 php: SSRF bypass in FILTER_VALIDATE_URL

https://bugzilla.redhat.com/show_bug.cgi?id=1978755

[ 2 ] Bug #1978790 - CVE-2021-21704 php: security issues in pdo_firebase module

https://bugzilla.redhat.com/show_bug.cgi?id=1978790

su -c 'dnf upgrade --advisory FEDORA-2021-172c8bd11d' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Product: Fedora 33
Version: 7.4.21
Release: 1.fc33
Summary: PHP scripting language for creating dynamic web sites

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here