Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia: 2022-0234 Critical Php Security Update - Buffer Overflow Issues

mageia
Calendar Grey June 18, 2022
Dist Mageia Esm H88
Mageia 2022-0235 rolls out essential python fixes tackling serious security threats. Check for comprehensive information.
CLI -Fixed bug #8575 (CLI closes standard streams too early)

Summary

CLI -Fixed bug #8575 (CLI closes standard streams too early). Core -Fixed Haiku ZTS builds. Date -Fixed bug #8471 (Segmentation fault when converting immutable and mutable DateTime instances created using reflection). php-fpm - Fixed bug #72185 writes empty fcgi record causing nginx 502. Mysqlnd - Fixed bug #81719: mysqlnd/pdo password buffer overflow. (CVE-2022-31626) OPcache - Fixed bug #8466 (ini_get() is optimized out when the option does not exist). Pcntl - Fixed Haiku build. Pgsql - Fixed bug #81720: Uninitialized array in pg_query_params(). (CVE-2022-31625) Soap - Fixed bug #8578 (Error on wrong parameter on SoapHeader constructor). Fixed bug #8538 (SoapClient may strip parts of nmtokens). SPL - Fixed bug #8235 (iterator_count() may run indefinitely). Zip - Fixed type for index in ZipArchive::replaceFile.

References

- https://bugs.mageia.org/show_bug.cgi?id=30533

- https://www.php.net/ChangeLog-8.php#8.0.20

- https://www.cve.org/CVERecord?id=CVE-2022-31625

- https://www.cve.org/CVERecord?id=CVE-2022-31626

Resolution

SRPMS

- 8/core/php-8.0.20-3.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 18 Jun 2022
URL: https://advisories.mageia.org/MGASA-2022-0234.html
Type: security
CVE: CVE-2022-31625, CVE-2022-31626

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here