Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Mageia 7: 2021-0025 Moderate: Php Data Validation Issue Fix

mageia
Calendar Grey January 14, 2021
Dist Mageia Esm H88
Mageia 2021-0036 tackles serious flaws in python security. It's essential that you upgrade your system to resolve these crucial vulnerabilities.
FILTER_VALIDATE_URL accepts URLs with invalid userinfo (CVE-2020-7071)

Summary

FILTER_VALIDATE_URL accepts URLs with invalid userinfo (CVE-2020-7071). stream_get_contents() fails with maxlength=-1 or default.
See upstream releasenotes for other changes.

References

- https://bugs.mageia.org/show_bug.cgi?id=28036

- https://www.php.net/ChangeLog-7.php#PHP_7_3_26

- https://www.cve.org/CVERecord?id=CVE-2020-7071

Resolution

SRPMS

- 7/core/php-7.3.26-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 14 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0025.html
Type: security
CVE: CVE-2020-7071

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here