Advisories ยป MGASA-2021-0519

Updated php packages fix security vulnerability

Publication date: 20 Nov 2021
Modification date: 20 Nov 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-21707

Description

Header injection via default_mimetype / default_charset
mbstring may use pointer from some previous request
Unexpected behavior with arrays and JIT
Special character is breaking the path in xml function (CVE-2021-21707)
XMLReader::getParserProperty may throw with a valid property
                

References

SRPMS

8/core