USN-7645-1

Source
https://ubuntu.com/security/notices/USN-7645-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7645-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7645-1
Upstream
Related
Published
2025-07-17T15:38:57.663259Z
Modified
2025-09-08T16:42:35Z
Summary
php7.0, php7.2 vulnerabilities
Details

It was discovered that PHP incorrectly parsed certain HTTP response headers. An attacker could possibly use this issue to cause incorrect MIME type parsing which could result in unexpected behavior. (CVE-2025-1217)

It was discovered that PHP did not properly validate certain HTTP headers. An attacker could possibly use this issue to perform an HTTP request smuggling attack. (CVE-2025-1734)

It was discovered that PHP did not properly validate certain HTTP headers. An attacker could possibly use this issue to prevent certain headers from being sent which could result in a denial of service or other unexpected behavior. (CVE-2025-1736)

It was discovered that PHP incorrectly performed URL truncation. An attacker could possibly use this issue to specially craft a URL that would result in unintended redirections or a denial of service. (CVE-2025-1861)

References

Affected packages

Ubuntu:Pro:16.04:LTS / php7.0

Package

Name
php7.0
Purl
pkg:deb/ubuntu/php7.0@7.0.33-0ubuntu0.16.04.16+esm15?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.0.33-0ubuntu0.16.04.16+esm15

Affected versions

7.*

7.0.1-5
7.0.1-6
7.0.2-1
7.0.2-3
7.0.2-4
7.0.2-5
7.0.3-2
7.0.3-3
7.0.3-9ubuntu1
7.0.4-5ubuntu1
7.0.4-5ubuntu2
7.0.4-7ubuntu1
7.0.4-7ubuntu2
7.0.4-7ubuntu2.1
7.0.8-0ubuntu0.16.04.1
7.0.8-0ubuntu0.16.04.2
7.0.8-0ubuntu0.16.04.3
7.0.13-0ubuntu0.16.04.1
7.0.15-0ubuntu0.16.04.1
7.0.15-0ubuntu0.16.04.2
7.0.15-0ubuntu0.16.04.4
7.0.18-0ubuntu0.16.04.1
7.0.22-0ubuntu0.16.04.1
7.0.25-0ubuntu0.16.04.1
7.0.28-0ubuntu0.16.04.1
7.0.30-0ubuntu0.16.04.1
7.0.32-0ubuntu0.16.04.1
7.0.33-0ubuntu0.16.04.1
7.0.33-0ubuntu0.16.04.2
7.0.33-0ubuntu0.16.04.3
7.0.33-0ubuntu0.16.04.4
7.0.33-0ubuntu0.16.04.5
7.0.33-0ubuntu0.16.04.6
7.0.33-0ubuntu0.16.04.7
7.0.33-0ubuntu0.16.04.9
7.0.33-0ubuntu0.16.04.11
7.0.33-0ubuntu0.16.04.12
7.0.33-0ubuntu0.16.04.14
7.0.33-0ubuntu0.16.04.15
7.0.33-0ubuntu0.16.04.16
7.0.33-0ubuntu0.16.04.16+esm1
7.0.33-0ubuntu0.16.04.16+esm2
7.0.33-0ubuntu0.16.04.16+esm3
7.0.33-0ubuntu0.16.04.16+esm4
7.0.33-0ubuntu0.16.04.16+esm5
7.0.33-0ubuntu0.16.04.16+esm6
7.0.33-0ubuntu0.16.04.16+esm7
7.0.33-0ubuntu0.16.04.16+esm8
7.0.33-0ubuntu0.16.04.16+esm9
7.0.33-0ubuntu0.16.04.16+esm10
7.0.33-0ubuntu0.16.04.16+esm11
7.0.33-0ubuntu0.16.04.16+esm12
7.0.33-0ubuntu0.16.04.16+esm13
7.0.33-0ubuntu0.16.04.16+esm14

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libapache2-mod-php7.0",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "libphp7.0-embed",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-bcmath",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-bz2",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-cgi",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-cli",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-common",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-curl",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-dba",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-dev",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-enchant",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-fpm",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-gd",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-gmp",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-imap",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-interbase",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-intl",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-json",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-ldap",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-mbstring",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-mcrypt",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-mysql",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-odbc",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-opcache",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-pgsql",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-phpdbg",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-pspell",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-readline",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-recode",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-snmp",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-soap",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-sqlite3",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-sybase",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-tidy",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-xml",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-xmlrpc",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-xsl",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        },
        {
            "binary_name": "php7.0-zip",
            "binary_version": "7.0.33-0ubuntu0.16.04.16+esm15"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Ubuntu:Pro:18.04:LTS / php7.2

Package

Name
php7.2
Purl
pkg:deb/ubuntu/php7.2@7.2.24-0ubuntu0.18.04.17+esm8?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.24-0ubuntu0.18.04.17+esm8

Affected versions

7.*

7.2.1-1ubuntu2
7.2.2-1ubuntu1
7.2.2-1ubuntu2
7.2.3-1ubuntu1
7.2.5-0ubuntu0.18.04.1
7.2.7-0ubuntu0.18.04.1
7.2.7-0ubuntu0.18.04.2
7.2.10-0ubuntu0.18.04.1
7.2.15-0ubuntu0.18.04.1
7.2.15-0ubuntu0.18.04.2
7.2.17-0ubuntu0.18.04.1
7.2.19-0ubuntu0.18.04.1
7.2.19-0ubuntu0.18.04.2
7.2.24-0ubuntu0.18.04.1
7.2.24-0ubuntu0.18.04.2
7.2.24-0ubuntu0.18.04.3
7.2.24-0ubuntu0.18.04.4
7.2.24-0ubuntu0.18.04.6
7.2.24-0ubuntu0.18.04.7
7.2.24-0ubuntu0.18.04.8
7.2.24-0ubuntu0.18.04.9
7.2.24-0ubuntu0.18.04.10
7.2.24-0ubuntu0.18.04.11
7.2.24-0ubuntu0.18.04.12
7.2.24-0ubuntu0.18.04.13
7.2.24-0ubuntu0.18.04.15
7.2.24-0ubuntu0.18.04.16
7.2.24-0ubuntu0.18.04.17
7.2.24-0ubuntu0.18.04.17+esm1
7.2.24-0ubuntu0.18.04.17+esm2
7.2.24-0ubuntu0.18.04.17+esm3
7.2.24-0ubuntu0.18.04.17+esm4
7.2.24-0ubuntu0.18.04.17+esm5
7.2.24-0ubuntu0.18.04.17+esm6
7.2.24-0ubuntu0.18.04.17+esm7

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libapache2-mod-php7.2",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "libphp7.2-embed",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-bcmath",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-bz2",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-cgi",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-cli",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-common",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-curl",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-dba",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-dev",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-enchant",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-fpm",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-gd",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-gmp",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-imap",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-interbase",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-intl",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-json",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-ldap",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-mbstring",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-mysql",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-odbc",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-opcache",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-pgsql",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-phpdbg",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-pspell",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-readline",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-recode",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-snmp",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-soap",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-sqlite3",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-sybase",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-tidy",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-xml",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-xmlrpc",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-xsl",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        },
        {
            "binary_name": "php7.2-zip",
            "binary_version": "7.2.24-0ubuntu0.18.04.17+esm8"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}