Release Info

Advisory: CLSA-2024:1727895152

OS: CentOS Stream 8 ELS

Public date: 2024-10-02 14:52:34

Project: php

Version: 7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1

Errata link: https://errata.tuxcare.com/els_os/centos-stream8els/CLSA-2024-1727895152.html

Changelog

- CVE-2020-7071: fix URL validation with functions like filter_var($url, FILTER_VALIDATE_URL) - CVE-2021-21705: fix URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter when an URL with invalid password field can be accepted as valid - CVE-2024-5458: fix early-out for ipv6 hostname validation, ensure full check is performed

Update

Update command: dnf update php*

Packages list

php-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-bcmath-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-cli-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-common-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-dba-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-dbg-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-devel-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-embedded-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-enchant-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-fpm-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-gd-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-gmp-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-intl-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-json-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-ldap-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-mbstring-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-mysqlnd-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-odbc-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-opcache-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-pdo-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-pgsql-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-process-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-recode-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-snmp-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-soap-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-xml-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm php-xmlrpc-7.2.24-1.module_el8+2215+5fe6689e.tuxcare.els1.x86_64.rpm

CVEs

CVE-2020-7071
CVE-2024-5458
CVE-2021-21705