Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 8: 2021-0519 Moderate: PHP Header Injection and XML Issues

mageia
Calendar Grey November 20, 2021
Dist Mageia Esm H88
Mageia 2021-0519 upgrades python components to resolve path traversal and buffer overflow vulnerabilities for improved protection.
Header injection via default_mimetype / default_charset mbstring may use pointer from some previous request Unexpected behavior with arrays and JIT Special character is breaking th...

Summary

Header injection via default_mimetype / default_charset mbstring may use pointer from some previous request Unexpected behavior with arrays and JIT Special character is breaking the path in xml function (CVE-2021-21707) XMLReader::getParserProperty may throw with a valid property

References

- https://bugs.mageia.org/show_bug.cgi?id=29673

- https://www.php.net/ChangeLog-8.php#8.0.13

- https://www.cve.org/CVERecord?id=CVE-2021-21707

Resolution

SRPMS

- 8/core/php-8.0.13-1.mga8

Publication date: 20 Nov 2021
URL: https://advisories.mageia.org/MGASA-2021-0519.html
Type: security
CVE: CVE-2021-21707

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here