MGASA-2019-0412

Source
https://advisories.mageia.org/MGASA-2019-0412.html
Import Source
https://advisories.mageia.org/MGASA-2019-0412.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0412
Related
  • CVE-2019-11045
  • CVE-2019-11046
  • CVE-2019-11047
  • CVE-2019-11049
  • CVE-2019-11050
Published
2019-12-25T19:08:41Z
Modified
2019-12-25T18:52:32Z
Summary
Updated php packages fix security vulnerabilities
Details

Updated php packages fix security vulnerabilities:

DirectoryIterator class silently truncates after a null byte (CVE-2019-11045).

Buffer underflow in bcshiftaddsub). (CVE-2019-11046)

Heap-buffer-overflow READ in exif. (CVE-2019-11047)

mail() may release string with refcount==1 twice. (CVE-2019-11049)

Use-after-free in exif parsing under memory sanitizer). (CVE-2019-11050)

For other fixes, see the referenced changelog.

References
Credits

Affected packages

Mageia:7 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.3.13-1.mga7

Ecosystem specific

{
    "section": "core"
}