| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
| |
CVE-2024-5458
|
|
|
|
|
|
|
| |
Fix __Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix
CVE-2024-2756
Fix password_verify can erroneously return true opening ATO risk
CVE-2024-3096
|
| |
|
|
|
|
|
|
|
| |
GHSA-3qrf-m4j2-pcrr CVE-2023-3823
Fix Buffer mismanagement in phar_dir_read()
GHSA-jqcx-ccgc-xwhv CVE-2023-3824
move httpd/nginx wants directive to config files in /etc
|
|
|
|
| |
define %php71___phpize and %php71___phpconfig
|
|
|
|
|
|
| |
authentication for SOAP
GHSA-76gg-c692-v2mw
use oracle client library version 21.10
|
|
|
|
|
|
|
|
| |
CVE-2023-0567
fix #81746: 1-byte array overrun in common path resolve code
CVE-2023-0568
fix DOS vulnerability when parsing multipart request body
CVE-2023-0662
|
|
|
|
|
| |
CVE-2022-31631
use oracle client library version 21.8
|
| |
|
|
|
|
|
|
| |
core: fix #81727 Don't mangle HTTP variable names that clash with ones
that have a specific semantic meaning. CVE-2022-31629
use oracle client library version 21.7
|
|
|
|
|
|
| |
core: fix #81727 Don't mangle HTTP variable names that clash with ones
that have a specific semantic meaning. CVE-2022-31629
use oracle client library version 21.7
|
|
|
|
|
| |
mysqlnd: fix #81719: mysqlnd/pdo password buffer overflow. CVE-2022-31626
pgsql: fix #81720: Uninitialized array in pg_query_params(). CVE-2022-31625
|
|
|
|
| |
CVE-2021-21707
|
|
|
|
|
|
| |
CVE-2021-21703
use libicu version 69
use oracle client library version 21.3
|
| |
|
| |
|
|
|
|
|
|
|
|
|
| |
CVE-2021-21705
Fix #76448 Stack buffer overflow in firebird_info_cb
Fix #76449 SIGSEGV in firebird_handle_doer
Fix #76450 SIGSEGV in firebird_stmt_execute
Fix #76452 Crash while parsing blob data in firebird_fetch_blob
CVE-2021-21704
|
| |
|
|
|
|
| |
use oracle client library version 21.1
|
|
|
|
|
| |
CVE-2021-21702
better fix for #77423
|
|
|
|
| |
CVE-2020-7071
|
|
|
|
|
|
|
|
|
| |
Fix #79699 PHP parses encoded cookie names so malicious `__Host-` cookies can be sent
CVE-2020-7070
OpenSSL:
Fix #79601 Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV
CVE-2020-7069
Fix bug #78079 openssl_encrypt_ccm.phpt fails with OpenSSL 1.1.1c
|
| |
|
|
|
|
|
|
|
| |
Fix #79877 getimagesize function silently truncates after a null byte
Phar:
Fix #79797 use of freed hash key in the phar_parse_zipfile function
CVE-2020-7068
|
|
|
|
|
|
|
| |
Fix #78875 Long filenames cause OOM and temp files are not cleaned
CVE-2019-11048
Fix #78876 Long variables in multipart/form-data cause OOM and temp
files are not cleaned
|
|
|
|
|
|
| |
Fix #79330 shell_exec silently truncates after a null byte
Fix #79465 OOB Read in urldecode
CVE-2020-7067
|
|
|
|
|
|
|
|
|
| |
Fix #79329 get_headers() silently truncates after a null byte
CVE-2020-7066
exif:
Fix #79282 Use-of-uninitialized-value in exif
CVE-2020-7064
use oracle client library version 19.6 (18.5 on EL-6)
|
| |
|
|
|
|
|
|
|
|
|
|
| |
Fix #77569 Write Access Violation in DomImplementation
phar:
Fix #79082 Files added to tar with Phar::buildFromIterator have all-access permissions
CVE-2020-7063
session:
Fix #79221 Null Pointer Dereference in PHP Session Upload Progress
CVE-2020-7062
|
| |
|
|
|
|
|
|
|
|
|
|
| |
Fix #79037 global buffer-overflow in mbfl_filt_conv_big5_wchar
CVE-2020-7060
session:
Fix #79091 heap use-after-free in session_create_id
standard:
Fix #79099 OOB read in php_strip_tags_ex
CVE-2020-7059
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Fix #78878 Buffer underflow in bc_shift_addsub
CVE-2019-11046
- core:
Fix #78862 link() silently truncates after a null byte on Windows
CVE-2019-11044
Fix #78863 DirectoryIterator class silently truncates after a null byte
CVE-2019-11045
- exif
Fix #78793 Use-after-free in exif parsing under memory sanitizer
CVE-2019-11050
Fix #78910 Heap-buffer-overflow READ in exif
CVE-2019-11047
- use oracle client library version 19.5 (18.5 on EL-6)
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
|
|
| |
add upstream patch for OpenSSL 1.1.1b
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|