--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2017-b8bb4b86e2
2017-07-18 19:26:12.549660
--------------------------------------------------------------------------------Name        : php
Product     : Fedora 26
Version     : 7.1.7
Release     : 1.fc26
URL         : https://www.php.net/
Summary     : PHP scripting language for creating dynamic web sites
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.

The php package contains the module (often referred to as mod_php)
which adds support for the PHP language to Apache HTTP Server.

--------------------------------------------------------------------------------Update Information:

**PHP version 7.1.7** (06 Jul 2017)  **Core:**  * Fixed bug php#74738 (Multiple
[PATH=] and [HOST=] sections not properly parsed). (Manuel Mausz) * Fixed bug
php#74658 (Undefined constants in array properties result in broken properties).
(Laruence) * Fixed misparsing of abstract unix domain socket names. (Sara) *
Fixed bug php#74603 (PHP INI Parsing Stack Buffer Overflow Vulnerability).
(Stas) * Fixed bug php#74101, bug php#74614 (Unserialize Heap Use-After-Free
(READ: 1) in zval_get_type). (Nikita) * Fixed bug php#74111 (Heap buffer
overread (READ: 1) finish_nested_data from unserialize). (Nikita) * Fixed bug
php#74819 (wddx_deserialize() heap out-of-bound read via php_parse_date()).
(Derick)  **Date:**  * Fixed bug php#74639 (implement clone for DatePeriod and
DateInterval). (andrewnester)  **DOM:**  * Fixed bug php#69373 (References to
deleted XPath query results). (ttoohey)  **Intl:**  * Fixed bug php#73473 (Stack
Buffer Overflow in msgfmt_parse_message). (libnex) * Fixed bug php#74705 (Wrong
reflection on Collator::getSortKey and collator_get_sort_key). (Tyson Andre,
Remi)  **Mbstring:**  * Add oniguruma upstream fix (CVE-2017-9224,
CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229) (Remi, Mamoru
TASAKA)  **Opcache:**  * Fixed bug php#74663 (Segfault with
opcache.memory_protect and validate_timestamp). (Laruence) * Revert
opcache.enable_cli to default disabled. (Nikita)  **OpenSSL:**  * Fixed bug
php#74720 (pkcs7_en/decrypt does not work if \x1a is used in content). (Anatol)
* Fixed bug php#74651 (negative-size-param (-1) in memcpy in
zif_openssl_seal()). (Stas)  **Reflection:**  * Fixed bug php#74673 (Segfault
when cast Reflection object to string with undefined constant). (Laruence)
**SPL:**  * Fixed bug php#74478 (null coalescing operator failing with
SplFixedArray). (jhdxr)  **FTP:**  * Fixed bug php#74598 (ftp:// wrapper ignores
context arg). (Sara)  **PHAR:**  * Fixed bug php#74386 (Phar::__construct
reflection incorrect). (villfa)  **SOAP**  * Fixed bug php#74679 (Incorrect
conversion array with WSDL_CACHE_MEMORY). (Dmitry)  **Streams:**  * Fixed bug
php#74556 (stream_socket_get_name() returns '\0'). (Sara)
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade php' at the command line.
For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora 26: php Security Update 2017-b8bb4b86e2

July 18, 2017
**PHP version 7.1.7** (06 Jul 2017) **Core:** * Fixed bug php#74738 (Multiple [PATH=] and [HOST=] sections not properly parsed)

Summary

PHP is an HTML-embedded scripting language. PHP attempts to make it

easy for developers to write dynamically generated web pages. PHP also

offers built-in database integration for several commercial and

non-commercial database management systems, so writing a

database-enabled webpage with PHP is fairly simple. The most common

use of PHP coding is probably as a replacement for CGI scripts.

The php package contains the module (often referred to as mod_php)

which adds support for the PHP language to Apache HTTP Server.

**PHP version 7.1.7** (06 Jul 2017) **Core:** * Fixed bug php#74738 (Multiple

[PATH=] and [HOST=] sections not properly parsed). (Manuel Mausz) * Fixed bug

php#74658 (Undefined constants in array properties result in broken properties).

(Laruence) * Fixed misparsing of abstract unix domain socket names. (Sara) *

Fixed bug php#74603 (PHP INI Parsing Stack Buffer Overflow Vulnerability).

(Stas) * Fixed bug php#74101, bug php#74614 (Unserialize Heap Use-After-Free

(READ: 1) in zval_get_type). (Nikita) * Fixed bug php#74111 (Heap buffer

overread (READ: 1) finish_nested_data from unserialize). (Nikita) * Fixed bug

php#74819 (wddx_deserialize() heap out-of-bound read via php_parse_date()).

(Derick) **Date:** * Fixed bug php#74639 (implement clone for DatePeriod and

DateInterval). (andrewnester) **DOM:** * Fixed bug php#69373 (References to

deleted XPath query results). (ttoohey) **Intl:** * Fixed bug php#73473 (Stack

Buffer Overflow in msgfmt_parse_message). (libnex) * Fixed bug php#74705 (Wrong

reflection on Collator::getSortKey and collator_get_sort_key). (Tyson Andre,

Remi) **Mbstring:** * Add oniguruma upstream fix (CVE-2017-9224,

CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229) (Remi, Mamoru

TASAKA) **Opcache:** * Fixed bug php#74663 (Segfault with

opcache.memory_protect and validate_timestamp). (Laruence) * Revert

opcache.enable_cli to default disabled. (Nikita) **OpenSSL:** * Fixed bug

php#74720 (pkcs7_en/decrypt does not work if \x1a is used in content). (Anatol)

* Fixed bug php#74651 (negative-size-param (-1) in memcpy in

zif_openssl_seal()). (Stas) **Reflection:** * Fixed bug php#74673 (Segfault

when cast Reflection object to string with undefined constant). (Laruence)

**SPL:** * Fixed bug php#74478 (null coalescing operator failing with

SplFixedArray). (jhdxr) **FTP:** * Fixed bug php#74598 (ftp:// wrapper ignores

context arg). (Sara) **PHAR:** * Fixed bug php#74386 (Phar::__construct

reflection incorrect). (villfa) **SOAP** * Fixed bug php#74679 (Incorrect

conversion array with WSDL_CACHE_MEMORY). (Dmitry) **Streams:** * Fixed bug

php#74556 (stream_socket_get_name() returns '\0'). (Sara)

su -c 'dnf upgrade php' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

FEDORA-2017-b8bb4b86e2 2017-07-18 19:26:12.549660 Product : Fedora 26 Version : 7.1.7 Release : 1.fc26 URL : https://www.php.net/ Summary : PHP scripting language for creating dynamic web sites Description : PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server. **PHP version 7.1.7** (06 Jul 2017) **Core:** * Fixed bug php#74738 (Multiple [PATH=] and [HOST=] sections not properly parsed). (Manuel Mausz) * Fixed bug php#74658 (Undefined constants in array properties result in broken properties). (Laruence) * Fixed misparsing of abstract unix domain socket names. (Sara) * Fixed bug php#74603 (PHP INI Parsing Stack Buffer Overflow Vulnerability). (Stas) * Fixed bug php#74101, bug php#74614 (Unserialize Heap Use-After-Free (READ: 1) in zval_get_type). (Nikita) * Fixed bug php#74111 (Heap buffer overread (READ: 1) finish_nested_data from unserialize). (Nikita) * Fixed bug php#74819 (wddx_deserialize() heap out-of-bound read via php_parse_date()). (Derick) **Date:** * Fixed bug php#74639 (implement clone for DatePeriod and DateInterval). (andrewnester) **DOM:** * Fixed bug php#69373 (References to deleted XPath query results). (ttoohey) **Intl:** * Fixed bug php#73473 (Stack Buffer Overflow in msgfmt_parse_message). (libnex) * Fixed bug php#74705 (Wrong reflection on Collator::getSortKey and collator_get_sort_key). (Tyson Andre, Remi) **Mbstring:** * Add oniguruma upstream fix (CVE-2017-9224, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229) (Remi, Mamoru TASAKA) **Opcache:** * Fixed bug php#74663 (Segfault with opcache.memory_protect and validate_timestamp). (Laruence) * Revert opcache.enable_cli to default disabled. (Nikita) **OpenSSL:** * Fixed bug php#74720 (pkcs7_en/decrypt does not work if \x1a is used in content). (Anatol) * Fixed bug php#74651 (negative-size-param (-1) in memcpy in zif_openssl_seal()). (Stas) **Reflection:** * Fixed bug php#74673 (Segfault when cast Reflection object to string with undefined constant). (Laruence) **SPL:** * Fixed bug php#74478 (null coalescing operator failing with SplFixedArray). (jhdxr) **FTP:** * Fixed bug php#74598 (ftp:// wrapper ignores context arg). (Sara) **PHAR:** * Fixed bug php#74386 (Phar::__construct reflection incorrect). (villfa) **SOAP** * Fixed bug php#74679 (Incorrect conversion array with WSDL_CACHE_MEMORY). (Dmitry) **Streams:** * Fixed bug php#74556 (stream_socket_get_name() returns '\0'). (Sara) su -c 'dnf upgrade php' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
Product : Fedora 26
Version : 7.1.7
Release : 1.fc26
URL : https://www.php.net/
Summary : PHP scripting language for creating dynamic web sites

Related News