Release Info

Advisory: CLSA-2025:1747690840

OS: Oracle Linux 7 ELS

Public date: 2025-05-19 21:40:42

Project: php

Version: 5.4.16-48.el7.tuxcare.els9

Errata link: https://errata.tuxcare.com/els_os/oraclelinux7els/CLSA-2025-1747690840.html

Changelog

- CVE-2025-1217: fix handling of folded headers by the http stream parser - CVE-2025-1734: fix validation of http headers with missing colon - CVE-2025-1861: fix incorrect http redirect location truncation

Update

Update command: yum update php*

Packages list

php-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-bcmath-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-cli-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-common-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-dba-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-devel-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-embedded-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-enchant-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-fpm-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-gd-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-intl-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-ldap-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-mbstring-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-mysql-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-mysqlnd-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-odbc-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-pdo-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-pgsql-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-process-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-pspell-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-recode-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-snmp-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-soap-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-xml-5.4.16-48.el7.tuxcare.els9.x86_64.rpm php-xmlrpc-5.4.16-48.el7.tuxcare.els9.x86_64.rpm

CVEs

CVE-2025-1861
CVE-2025-1734
CVE-2025-1217