From b7b9302660a23a67285e204bc3d7fcf6ba7f6533 Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Tue, 17 Mar 2020 07:25:12 +0100 Subject: [PATCH] Fix bug #79329 - get_headers should not accept \0 From 0d139c5b94a5f485a66901919e51faddb0371c43 --- ext/standard/url.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ext/standard/url.c b/ext/standard/url.c index 0eac03ee0a..39e5b1b2c2 100644 --- a/ext/standard/url.c +++ b/ext/standard/url.c @@ -660,7 +660,7 @@ PHP_FUNCTION(get_headers) zval *zcontext = NULL; php_stream_context *context; - if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|lr!", &url, &url_len, &format, &zcontext) == FAILURE) { + if (zend_parse_parameters(ZEND_NUM_ARGS(), "p|lr!", &url, &url_len, &format, &zcontext) == FAILURE) { return; } From 03471e31c9b467d1d8d944e44fa009ef247e81bd Mon Sep 17 00:00:00 2001 From: Stanislav Malyshev Date: Sun, 15 Mar 2020 19:35:26 -0700 Subject: [PATCH] [ci skip] Update NEWS (cherry picked from commit c8d21d7728109b0f911033c098cfaeb7438ba1d5) --- NEWS | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/NEWS b/NEWS index 4233a530c1..f0bec6aa69 100644 --- a/NEWS +++ b/NEWS @@ -1,6 +1,16 @@ PHP NEWS ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| +Backported from 7.2.29 + +- Core: + . Fixed bug #79329 (get_headers() silently truncates after a null byte) + (CVE-2020-7066) (cmb) + +- EXIF: + . Fixed bug #79282 (Use-of-uninitialized-value in exif) (CVE-2020-7064) + (Nikita) + Backported from 7.2.28 - DOM: