MGASA-2021-0025 - Updated php packages fix security vulnerability Publication date: 14 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0025.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-7071 FILTER_VALIDATE_URL accepts URLs with invalid userinfo (CVE-2020-7071). stream_get_contents() fails with maxlength=-1 or default. See upstream releasenotes for other changes. References: - https://bugs.mageia.org/show_bug.cgi?id=28036 - https://www.php.net/ChangeLog-7.php#PHP_7_3_26 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7071 SRPMS: - 7/core/php-7.3.26-1.mga7