Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia 7: MGASA-2020-0178 Critical: PHP OOB Read and Overflow Fix

mageia
Calendar Grey April 20, 2020
Dist Mageia Esm H88
Debian's Python Upgrade Tackles Key Flaws Like Buffer Overflow and Heap Corruption Risks.
Updated php packages fix security vulnerabilities: - OOB Read in urldecode() (CVE-2020-7067) - Integer Overflow in shmop_open() Noteable changes:

Summary

Updated php packages fix security vulnerabilities: - OOB Read in urldecode() (CVE-2020-7067) - Integer Overflow in shmop_open()
Noteable changes: - Opcache chokes and uses 100% CPU on specific script - curl_copy_handle() memory leak - ZipArchive::open fails on empty file

References

- https://bugs.mageia.org/show_bug.cgi?id=26491

- https://www.php.net/ChangeLog-7.php#7.3.17

- https://www.cve.org/CVERecord?id=CVE-2020-7067

Resolution

SRPMS

- 7/core/php-7.3.17-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 20 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0178.html
Type: security
CVE: CVE-2020-7067

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here