Advisories ยป MGASA-2019-0412

Updated php packages fix security vulnerabilities

Publication date: 25 Dec 2019
Modification date: 25 Dec 2019
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-11045 , CVE-2019-11046 , CVE-2019-11047 , CVE-2019-11049 , CVE-2019-11050

Description

Updated php packages fix security vulnerabilities:

DirectoryIterator class silently truncates after a null byte
(CVE-2019-11045).

Buffer underflow in bc_shift_addsub). (CVE-2019-11046)

Heap-buffer-overflow READ in exif. (CVE-2019-11047)

mail() may release string with refcount==1 twice. (CVE-2019-11049)

Use-after-free in exif parsing under memory sanitizer). (CVE-2019-11050)

For other fixes, see the referenced changelog.
                

References

SRPMS

7/core