Updated php packages fix security vulnerabilities:
Two buffer overflows in string and mbstring handling have been found
(CVE-2020-7059, CVE-2020-7060).
Other security fixes have been applied:
- Session: Fixed bug #79091 (heap use-after-free in session_create_id()).
- Date: Fixed bug #79015 (undefined-behavior in php_date.c).
For other fixes in this update, see the referenced chagelog.
- https://bugs.mageia.org/show_bug.cgi?id=26126
- https://www.php.net/ChangeLog-7.php#7.3.14
- https://www.cve.org/CVERecord?id=CVE-2020-7059
- https://www.cve.org/CVERecord?id=CVE-2020-7060
- 7/core/php-7.3.14-1.mga7
Get the latest Linux and open source security news straight to your inbox.