MGASA-2021-0330

Source
https://advisories.mageia.org/MGASA-2021-0330.html
Import Source
https://advisories.mageia.org/MGASA-2021-0330.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0330
Related
Published
2021-07-10T12:56:54Z
Modified
2021-07-10T11:36:15Z
Summary
Updated php packages fix security vulnerabilities
Details

Updated php packages provides upstream 8.0.8 and fixes the following security vulnerabilities:

  • PDO_Firebird:
    • Fix Stack buffer overflow in firebirdinfocb (CVE-2021-21704).
    • Fix SIGSEGV in firebirdhandledoer (CVE-2021-21704).
    • Fix SIGSEGV in firebirdstmtexecute (CVE-2021-21704).
    • Fix Crash while parsing blob data in firebirdfetchblob (CVE-2021-21704)
  • Fix SSRF bypass in FILTERVALIDATEURL (CVE-2021-21705).

For other fixes in this update, see the referenced Changelog.

References
Credits

Affected packages

Mageia:8 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.8-1.1.mga8

Ecosystem specific

{
    "section": "core"
}