Release Info

Advisory: CLSA-2025:1756483990

OS: CentOS 6 ELS

Public date: 2025-08-29 16:13:12.741955

Project: php

Version: 5.3.3-55.el6.tuxcare.els14

Errata link: https://errata.tuxcare.com/els_os/centos6els/CLSA-2025-1756483990.html

Changelog

- CVE-2025-1217: http stream wrapper: fix handling folded headers - CVE-2025-1734: http stream wrapper: fix handling headers with invalid name and no colon - CVE-2025-1861: fix http redirect location truncation

Update

Update command: yum update php*

Packages list

php-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-bcmath-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-cli-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-common-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-dba-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-devel-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-embedded-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-enchant-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-fpm-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-gd-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-imap-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-intl-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-ldap-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-mbstring-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-mysql-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-odbc-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-pdo-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-pgsql-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-process-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-pspell-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-recode-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-snmp-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-soap-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-tidy-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-xml-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-xmlrpc-5.3.3-55.el6.tuxcare.els14.x86_64.rpm php-zts-5.3.3-55.el6.tuxcare.els14.x86_64.rpm

CVEs

CVE-2025-1217
CVE-2025-1861
CVE-2025-1734