UbuntuUpdates.org

Bugs fixes in "php7.4"

Origin Bug number Title Date fixed
CVE CVE-2023-0567 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3 ... 2023-02-28
CVE CVE-2023-0662 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consump 2023-02-28
CVE CVE-2023-0568 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolv 2023-02-28
CVE CVE-2023-0567 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3 ... 2023-02-28
CVE CVE-2023-0662 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consump 2023-02-28
CVE CVE-2023-0568 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolv 2023-02-28
CVE CVE-2023-0567 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3 ... 2023-02-28
CVE CVE-2023-0662 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consump 2023-02-28
CVE CVE-2023-0568 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolv 2023-02-28
CVE CVE-2023-0567 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3 ... 2023-02-28
Launchpad 1999598 Don't throw an error when serializing uninitialized typed properties with __sleep() 2023-01-16
Launchpad 1989196 Fix PHP_EXTRA_VERSION setting 2023-01-16
Launchpad 1999598 Don't throw an error when serializing uninitialized typed properties with __sleep() 2023-01-16
Launchpad 1989196 Fix PHP_EXTRA_VERSION setting 2023-01-16
Launchpad 1999598 Don't throw an error when serializing uninitialized typed properties with __sleep() 2023-01-05
Launchpad 1999598 Don't throw an error when serializing uninitialized typed properties with __sleep() 2023-01-05
CVE CVE-2022-37454 The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute 2022-11-08
CVE CVE-2022-31629 In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the 2022-11-08
CVE CVE-2022-31628 In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infini 2022-11-08
CVE CVE-2022-37454 The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute 2022-11-08



About   -   Send Feedback to @ubuntu_updates