MGASA-2020-0119

Source
https://advisories.mageia.org/MGASA-2020-0119.html
Import Source
https://advisories.mageia.org/MGASA-2020-0119.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0119
Upstream
Published
2020-03-06T16:13:58Z
Modified
2026-04-16T00:10:55Z
Summary
Updated php packages fix bugs and security vulnerabilities
Details

Updated php packages fix bugs and security vulnerabilities:

Core:

  • Fixed bug #71876 (Memory corruption htmlspecialchars(): charset `*' not supported).
  • Fixed bug #79146 (cscript can fail to run on some systems).
  • Fixed bug #78323 (Code 0 is returned on invalid options).
  • Fixed bug #76047 (Use-after-free when accessing already destructed backtrace arguments). CURL:
  • Fixed bug #79078 (Hypothetical use-after-free in curl_multi_add_handle()). Intl:
  • Fixed bug #79212 (NumberFormatter::format() may detect wrong type). Libxml:
  • Fixed bug #79191 (Error in SoapClient ctor disables DOMDocument::save()). MBString:
  • Fixed bug #79154 (mb_convert_encoding() can modify $from_encoding). MySQLnd:
  • Fixed bug #79084 (mysqlnd may fetch wrong column indexes with MYSQLI_BOTH). OpenSSL:
  • Fixed bug #79145 (openssl memory leak). Phar:
  • Fixed bug #79082 (Files added to tar with Phar::buildFromIterator have all-access permissions). (CVE-2020-7063)
  • Fixed bug #79171 (heap-buffer-overflow in phar_extract_file). (CVE-2020-7061)
  • Fixed bug #76584 (PharFileInfo::decompress not working). Reflection:
  • Fixed bug #79115 (ReflectionClass::isCloneable call reflected class __destruct). Session:
  • Fixed bug #79221 (Null Pointer Dereference in PHP Session Upload Progress). (CVE-2020-7062) SPL:
  • Fixed bug #79151 (heap use after free caused by spl_dllist_it_helper_move_forward). Standard:
  • Fixed bug #78902 (Memory leak when using stream_filter_append). XSL:
  • Fixed bug #70078 (XSL callbacks with nodes as parameter leak memory).
References
Credits

Affected packages

Mageia:7 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.3.15-1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2020-0119.json"