Advisories ยป MGASA-2021-0025

Updated php packages fix security vulnerability

Publication date: 14 Jan 2021
Modification date: 14 Jan 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-7071

Description

FILTER_VALIDATE_URL accepts URLs with invalid userinfo (CVE-2020-7071).
stream_get_contents() fails with maxlength=-1 or default.

See upstream releasenotes for other changes.
                

References

SRPMS

7/core