Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Mageia 7 Security Advisory: 2020-0148 Critical: PHP Memory Corruption

mageia
Calendar Grey March 31, 2020
Dist Mageia Esm H88
Mageia has rolled out new updates for essential PHP packages to tackle significant security flaws and urgent bugs.
Critical bugs closed: - Use-of-uninitialized-value in exif [1] - mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full [2] - get_headers() silently truncates ...

Summary

Critical bugs closed: - Use-of-uninitialized-value in exif [1] - mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full [2] - get_headers() silently truncates after a null byte [3]
Some more bugs closed, as: - Memory corruption in preg_replace/preg_replace_callback and unicode - restore_error_handler does not restore previous errors mask

References

- https://bugs.mageia.org/show_bug.cgi?id=26365

- https://www.php.net/ChangeLog-7.php#7.3.16

- https://www.cve.org/CVERecord?id=CVE-2020-7064

- https://www.cve.org/CVERecord?id=CVE-2020-7065

- https://www.cve.org/CVERecord?id=CVE-2020-7066

Resolution

SRPMS

- 7/core/php-7.3.16-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 01 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0148.html
Type: security
CVE: CVE-2020-7064, CVE-2020-7065, CVE-2020-7066

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here