Mageia 2021-0025: php security update
Summary
FILTER_VALIDATE_URL accepts URLs with invalid userinfo (CVE-2020-7071).
stream_get_contents() fails with maxlength=-1 or default.
See upstream releasenotes for other changes.
References
- https://bugs.mageia.org/show_bug.cgi?id=28036
- https://www.php.net/ChangeLog-7.php#PHP_7_3_26
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7071
Resolution
MGASA-2021-0025 - Updated php packages fix security vulnerability
SRPMS
- 7/core/php-7.3.26-1.mga7