MGASA-2022-0406

Source
https://advisories.mageia.org/MGASA-2022-0406.html
Import Source
https://advisories.mageia.org/MGASA-2022-0406.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0406
Published
2022-11-01T22:58:59Z
Modified
2026-04-16T04:22:55Z
Summary
Updated php packages fix security vulnerability
Details

GD - Fixed bug #81739: OOB read due to insufficient input validation in imageloadfont(). Hash - Fixed bug #81738: buffer overflow in hash_update() on long parameter. Session - Fixed bug GH-9583 (session_create_id() fails with user defined save handler that doesn't have a validateId() method). Streams - Fixed bug GH-9590 (stream_select does not abort upon exception or empty valid fd set)

References
Credits

Affected packages

Mageia:8 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.0.25-1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2022-0406.json"