Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Mageia 7 Security Advisory: 2020-0148 Critical: PHP Memory Corruption

mageia
Calendar Grey March 31, 2020
Scroller Mageia
Mageia has rolled out new updates for essential PHP packages to tackle significant security flaws and urgent bugs.
Critical bugs closed: - Use-of-uninitialized-value in exif [1] - mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full [2] - get_headers() silently truncates ...

Summary

Critical bugs closed: - Use-of-uninitialized-value in exif [1] - mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full [2] - get_headers() silently truncates after a null byte [3]
Some more bugs closed, as: - Memory corruption in preg_replace/preg_replace_callback and unicode - restore_error_handler does not restore previous errors mask

References

- https://bugs.mageia.org/show_bug.cgi?id=26365

- https://www.php.net/ChangeLog-7.php#7.3.16

- https://www.cve.org/CVERecord?id=CVE-2020-7064

- https://www.cve.org/CVERecord?id=CVE-2020-7065

- https://www.cve.org/CVERecord?id=CVE-2020-7066

Resolution

SRPMS

- 7/core/php-7.3.16-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 01 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0148.html
Type: security
CVE: CVE-2020-7064, CVE-2020-7065, CVE-2020-7066

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.