The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
**PHP version 7.4.28** (17 Feb 2022) **Filter:** * Fixed bug php#81708: UAF due to php_filter_float() failing for ints (**CVE-2021-21708**)
Researchers discovered a number of severe security bugs leading to code execution in the WordPress…Critical Code Execution Bugs Found In PHP Everywhere WordPre…
Running PHP on a Linux web server is a prerequisite for the use of many popular applications such as Wordpress, Joomla and Drupal. Linux administrators and web…
Updated php packages fix security vulnerability: In PHP versions 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and…
PHP-PFM in PHP could be made to run program as an administrator if it received specially crafted input.
Updated php-pear packages fix security vulnerability: In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive (CVE-2021-32…
An update for rh-php73-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Mod…
Updated php packages provides upstream 8.0.8 and fixes the following security vulnerabilities: - PDO_Firebird: * Fix Stack buffer overflow in firebird_info_cb …
The package php before version 8.0.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.
Several security issues were fixed in PHP.
Updated PHP packages fix security vulnerabilities: - Fixed bug #81122: SSRF bypass in FILTER_VALIDATE_URL. (CVE-2021-21705) PDO_Firebird: - Fixed bug #76448: S…
**Version 6.5.0** (June 16th, 2021) * **SECURITY** Fixes **CVE-2021-34551**, a complex RCE affecting Windows hosts. See SECURITY.md for details. * The fix for …
**Version 6.5.0** (June 16th, 2021) * **SECURITY** Fixes **CVE-2021-34551**, a complex RCE affecting Windows hosts. See SECURITY.md for details. * The fix for …
A serious security vulnerability existed in the PHP Composer package. Exploiting this bug could allow…Vulnerability In PHP Composer Package Could Allow Supply-…
Cyku Hong from DEVCORE discovered that php-nette, a PHP MVC framework, is vulnerable to a code injection attack by passing specially formed parameters to URL t…
In PHP versions 7.2.x when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host …
**PHP version 7.3.23** (01 Oct 2020) **Core:** * Fixed bug php#80048 (Bug php#69100 has not been fixed for Windows). (cmb) * Fixed bug php#80049 (Memleak when …
**PHP version 7.4.11** (01 Oct 2020) **Core:** * Fixed bug php#79699 (PHP parses encoded cookie names so malicious `__Host-` cookies can be sent). (**CVE-2020-…
**PHP version 7.4.11** (01 Oct 2020) **Core:** * Fixed bug php#79699 (PHP parses encoded cookie names so malicious `__Host-` cookies can be sent). (**CVE-2020-…
A vulnerabilities in PHP could lead to a Denial of Service condition.
An update for the php:7.3 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of…
Updated php packages fix security vulnerabilities: - Fixed bug #78875 (Long filenames cause OOM and temp files are not cleaned). [1] - Fixed bug #78876 (Long v…
PHP could be made to crash if it received a specially crafted file.
**PHP version 7.3.18** (14 May 2020) **Core:** * Fixed bug php#78875 (Long filenames cause OOM and temp files are not cleaned). (**CVE-2019-11048**) (cmb) * Fi…