MGASA-2024-0132

Source
https://advisories.mageia.org/MGASA-2024-0132.html
Import Source
https://advisories.mageia.org/MGASA-2024-0132.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2024-0132
Upstream
Published
2024-04-13T16:56:38Z
Modified
2026-04-16T04:43:28Z
Summary
Updated php packages fix security vulnerabilities
Details

Core:

  • Corrupted memory in destructor with weak references
  • GC does not scale well with a lot of objects created in destructor DOM:
  • Add some missing ZPP checks.
  • Fix potential memory leak in XPath evaluation results. FPM:
  • Fix incorrect check in fpm_shm_free(). Gettext:
  • Fixed sigabrt raised with dcgettext/dcngettext calls with gettext 0.22.5 with category set to LC_ALL. MySQLnd:
  • Fixed handshake response [mysqlnd]
  • Fix incorrect charset length in check_mb_eucjpms(). Opcache:
  • JITed QM_ASSIGN may be optimized out when op1 is null
  • Segmentation fault for enabled observers when calling trait method of internal trait when opcache is loaded PDO:
  • Fix various PDORow bugs. Random:
  • Pre-PHP 8.2 compatibility for mt_srand with unknown modes
  • Global Mt19937 is not properly reset in-between requests when MT_RAND_PHP is used Session:
  • Segfault with session_decode and compilation error Sockets:
  • socket_getsockname returns random characters in the end of the socket name SPL:
  • Unable to resize SplfixedArray after being unserialized in PHP 8.2.15
  • Unexpected null pointer in zend_string.h Standard:
  • Added validation of \n in $additional_headers of mail()
  • Command injection via array-ish $command parameter of proc_open). (CVE-2024-1874) Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix). (CVE-2024-2756)
  • password_verify can erroneously return true, opening ATO risk. (CVE-2024-3096)
References
Credits

Affected packages

Mageia:9 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.2.18-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2024-0132.json"