From 58848d2a0001a7f71483c1756cd8a23f2c37455d Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Wed, 25 Aug 2021 16:51:45 +0200 Subject: Fix #81211 Symlinks are followed when creating PHAR archive --- php71.spec | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) (limited to 'php71.spec') diff --git a/php71.spec b/php71.spec index 320bab1..bda5455 100644 --- a/php71.spec +++ b/php71.spec @@ -109,7 +109,7 @@ Summary: PHP scripting language for creating dynamic web sites Name: php Version: %{upver}%{?rcver:~%{rcver}} -Release: 15%{?dist} +Release: 16%{?dist} # All files licensed under PHP version 3.01, except # Zend is licensed under Zend # TSRM is licensed under BSD @@ -195,6 +195,7 @@ Patch223: php-bug80672.patch Patch224: php-bug80710.patch Patch225: php-bug81122.patch Patch226: php-bug76450.patch +Patch227: php-bug81211.patch # Fixes for tests (300+) # Factory is droped from system tzdata @@ -1077,6 +1078,7 @@ support for JavaScript Object Notation (JSON) to PHP. %patch224 -p1 -b .bug80710 %patch225 -p1 -b .bug81122 %patch226 -p1 -b .bug76450 +%patch227 -p1 -b .bug81211 # Fixes for tests %if 0%{?fedora} >= 25 || 0%{?rhel} >= 6 @@ -2151,6 +2153,9 @@ EOF %changelog +* Wed Aug 25 2021 Remi Collet - 7.1.33-16 +- Fix #81211 Symlinks are followed when creating PHAR archive + * Mon Jun 28 2021 Remi Collet - 7.1.33-15 - Fix #81122 SSRF bypass in FILTER_VALIDATE_URL CVE-2021-21705 -- cgit