Updated php packages fix security vulnerabilities:
DirectoryIterator class silently truncates after a null byte
(CVE-2019-11045).
Buffer underflow in bc_shift_addsub). (CVE-2019-11046)
Heap-buffer-overflow READ in exif. (CVE-2019-11047)
mail() may release string with refcount==1 twice. (CVE-2019-11049)
Use-after-free in exif parsing under memory sanitizer). (CVE-2019-11050)
For other fixes, see the referenced changelog.
- https://bugs.mageia.org/show_bug.cgi?id=25894
- https://www.php.net/ChangeLog-7.php#7.3.13
- https://www.cve.org/CVERecord?id=CVE-2019-11045
- https://www.cve.org/CVERecord?id=CVE-2019-11046
- https://www.cve.org/CVERecord?id=CVE-2019-11047
- https://www.cve.org/CVERecord?id=CVE-2019-11049
- https://www.cve.org/CVERecord?id=CVE-2019-11050
- 7/core/php-7.3.13-1.mga7
Get the latest Linux and open source security news straight to your inbox.