Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8: 2022-0456 Critical Update for Python Security and Memory Fixes

mageia
Calendar Grey July 4, 2021
Dist Mageia Esm H88
The latest modifications to PHP libraries tackle critical security flaws, resolving issues related to SSRF evasion and stack overflow errors in Mageia 7.
Updated PHP packages fix security vulnerabilities: - Fixed bug #81122: SSRF bypass in FILTER_VALIDATE_URL

Summary

Updated PHP packages fix security vulnerabilities: - Fixed bug #81122: SSRF bypass in FILTER_VALIDATE_URL. (CVE-2021-21705)
PDO_Firebird: - Fixed bug #76448: Stack buffer overflow in firebird_info_cb. (CVE-2021-21704) - Fixed bug #76449: SIGSEGV in firebird_handle_doer. (CVE-2021-21704) - Fixed bug #76450: SIGSEGV in firebird_stmt_execute. (CVE-2021-21704) - Fixed bug #76452: Crash while parsing blob data in firebird_fetch_blob. (CVE-2021-21704)

References

- https://bugs.mageia.org/show_bug.cgi?id=29197

- https://www.php.net/ChangeLog-7.php#7.3.29

- https://www.cve.org/CVERecord?id=CVE-2021-21704

- https://www.cve.org/CVERecord?id=CVE-2021-21705

Resolution

SRPMS

- 7/core/php-7.3.29-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 04 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0312.html
Type: security
CVE: CVE-2021-21704, CVE-2021-21705

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here