Collected every two hours from specialised publications — each link leads to the original article.
Several security issues were fixed in PHP.
PHP version 8.3.14 (21 Nov 2024) CLI: Fixed bug GH-16373 (Shebang is not skipped for router script in cli-server started through shebang). (ilutov) Fixed bug G…
New php packages are available for Slackware 15.0 and -current to fix security issues.
bartlett/php-compatinfo-db 6.12.0 - 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support
bartlett/php-compatinfo-db 6.12.0 - 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support
Several security issues were fixed in PHP.
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection f…
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection f…
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection f…
It was discovered that there was a potential XSS vulnerability in php-horde-mime-viewer, a MIME viewer library for the Horde groupware platform.
It was discovered that there was an arbitrary object deserialization vulnerability in php-horde-turba, an address book component for the Horde groupware suite.
PHP version 8.2.24 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fi…
PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fi…
PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fi…
Several security issues were fixed in PHP.
Fabien Potencier discovered that under some conditions the sandbox mechanism of Twig, a template engine for PHP, could by bypassed. For the stable distribution…
A possible sandbox bypass has been fixed in php-twig, a template engine for PHP For Debian 11 bullseye, this problem has been fixed in version
PHP could be made to accept invalid URLs.
Multiple vulnerabilities have been discovered in PHP, the worst of which can lead to a denial of service.
This update ships the latest version of php 8.2. It brings fixed security issues and the usual bug fixes. Vulnerability: A code logic error, filtering function…
PHP version 8.2.20 (06 Jun 2024) CGI: Fixed buffer limit on Windows, replacing read call usage by _read. (David Carlier) Fixed bug GHSA-3qgc-jrrr-25jv (Bypass …
PHP version 8.3.8 (06 Jun 2024) CGI: Fixed buffer limit on Windows, replacing read call usage by _read. (David Carlier) Fixed bug GHSA-3qgc-jrrr-25jv (Bypass o…
New php packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in PHP.