MGASA-2021-0442

Source
https://advisories.mageia.org/MGASA-2021-0442.html
Import Source
https://advisories.mageia.org/MGASA-2021-0442.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0442
Published
2021-09-29T17:22:22Z
Modified
2026-04-16T04:24:33Z
Summary
Updated php packages fix security vulnerabilities
Details

Updated php packages fix security vulnerabilities:

  • Integer overflow in mysqli_real_escape_string()
  • Symlinks are followed when creating PHAR archive
  • shmop can't read beyond 2147483647 bytes
  • Integer overflow on substr_replace
  • Heap buffer overflow via str_repeat
  • Integer Overflow when concatenating strings
  • segfault with preloading and statically bound closure
  • shmop_open won't attach and causes php to crash
  • Heap Overflow in msg_send
  • ZipArchive::extractTo extracts outside of destination
References
Credits

Affected packages

Mageia:8 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.0.11-1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0442.json"