Red Hat Security Advisory: php:7.3 security, bug fix, and enhancement update
🔗 CVE IDs covered (22)
📋 Description
CVE-2019-11039 — php: Out-of-bounds read due to integer overflow in iconv_mime_decode_headers() CVE-2019-11040 — php: Buffer over-read in exif_read_data() CVE-2019-11041 — php: Heap buffer over-read in exif_scan_thumbnail() CVE-2019-11042 — php: Heap buffer over-read in exif_process_user_comment() CVE-2019-11045 — php: DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte CVE-2019-11047 — php: Information disclosure in exif_read_data() CVE-2019-11048 — php: Integer wraparounds when receiving multipart forms CVE-2019-11050 — php: Out of bounds read when parsing EXIF information CVE-2019-13224 — oniguruma: Use-after-free in onig_new_deluxe() in regext.c CVE-2019-13225 — oniguruma: NULL pointer dereference in match_at() in regexec.c CVE-2019-16163 — oniguruma: Stack exhaustion in regcomp.c because of recursion in regparse.c CVE-2019-19203 — oniguruma: Heap-based buffer over-read in function gb18030_mbc_enc_len in file gb18030.c CVE-2019-19204 — oniguruma: Heap-based buffer over-read in function fetch_interval_quantifier in regparse.c CVE-2019-19246 — oniguruma: Heap-based buffer overflow in str_lower_case_match in regexec.c CVE-2019-20454 — pcre: Out of bounds read in JIT mode when \X is used in non-UTF mode CVE-2020-7059 — php: Out of bounds read in php_strip_tags_ex CVE-2020-7060 — php: Global buffer-overflow in mbfl_filt_conv_big5_wchar function CVE-2020-7062 — php: NULL pointer dereference in PHP session upload progress CVE-2020-7063 — php: Files added to tar with Phar::buildFromIterator have all-access permissions CVE-2020-7064 — php: Information disclosure in exif_read_data() function CVE-2020-7065 — php: Using mb_strtolower() function with UTF-32LE encoding leads to potential code execution CVE-2020-7066 — php: Information disclosure in function get_headers
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2020:3662
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1724152
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1724154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1728965
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1728970
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735494
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1739459
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1739465
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1768997
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1777537
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1786570
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1786572
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1788258
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797776
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1797779
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802061
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1802068
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1808532
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1808536
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820601
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820604
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820627
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1837842
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3662.json