The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Several security issues were fixed in PHP.
An update for the php:8.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of…
**PHP version 8.1.12** (27 Oct 2022) **Core:** * Fixes segfault with Fiber on FreeBSD i386 architecture. (David Carlier) **Fileinfo:** * Fixed bug [GH-8805](ht…
**PHP version 8.0.25** (27 Oct 2022) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**) (cmb…
## [3.1.47] - 2022-09-14 ### Security - Applied appropriate javascript and html escaping in mailto plugin to counter injection attacks [#454](https://github.co…
**PHP version 8.0.24** (29 Sep 2022) **Core:** * Fixed bug [GH-9323](https://github.com/php/php-src/issues/9323) (Crash in ZEND_RETURN/GC/zend_call_function) (…
Marlon Starkloff discovered that twig, a template engine for PHP, did not correctly enforce sandboxing. This would allow a malicious user to execute arbitrary …
An update for php is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A C…
PHP could be made to crash or run programs if it processed specially crafted data.
Several security issues were fixed in PHP.
An update for rh-php73-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Imp…
CLI -Fixed bug #8575 (CLI closes standard streams too early). Core -Fixed Haiku ZTS builds. Date -Fixed bug #8471 (Segmentation fault when converting immutable…
**PHP version 8.0.20** (09 Jun 2022) **CLI:** * Fixed bug [GH-8575](https://github.com/php/php-src/issues/8575) (CLI closes standard streams too early). (Levi …
Template authors could inject php code by choosing a malicious {block} name or {include} file name. (CVE-2022-29221) References: - https://bugs.mageia.org/show…
Updated php-smarty packages to version 4 for php 8 compatibility and to fix security vulnerabilities. References: - https://bugs.mageia.org/show_bug.cgi?id=302…
Marlon Starkloff discovered that twig, a template engine for PHP, did not correctly enforce sandboxing. This would allow a malicious user to execute arbitrary …
Several security issues were fixed in PHP.
Several security issues were fixed in PHP.
Security update for php. See changelog for details. References: - https://bugs.mageia.org/show_bug.cgi?id=30056 - https://www.php.net/ChangeLog-8.php#8.0.16
PHP could be made to crash or run programs if it received specially crafted input.
**PHP version 7.4.28** (17 Feb 2022) **Filter:** * Fixed bug php#81708: UAF due to php_filter_float() failing for ints (**CVE-2021-21708**)
**PHP version 8.0.16** (17 Feb 2022) **Core:** * Fixed bug php#81430 (Attribute instantiation leaves dangling pointer). (beberlei) * Fixed bug [GH-7896](https:…
New php packages are available for Slackware 15.0 and -current to fix a security issue.
Researchers discovered a number of severe security bugs leading to code execution in the WordPress…Critical Code Execution Bugs Found In PHP Everywhere WordPre…