Opened 10 months ago
Closed 10 months ago
#19908 closed enhancement (fixed)
php-8.3.8
Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
---|---|---|---|
Priority: | high | Milestone: | 12.2 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New point version.
Change History (3)
comment:2 by , 10 months ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:3 by , 10 months ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Fixed at f7aa1d4c36c2954e0afae053cf9bbdf47ceeb787
SA-12.1-057 issued
Note:
See TracTickets
for help on using tickets.
Release notes:
06 Jun 2024
CGI:
CLI:
Core:
DOM:
Filter:
FPM:
Hash:
__has_builtin
and__GNUC__
Intl:
MySQLnd:
Opcache:
OpenSSL:
Standard:
XML:
XMLReader:
This brings CVE-2024-4577 (a bypass of CVE-2012-1823), CVE-2024-5458, CVE-2024-5585, and an implementation of the Marvin Attack in PHP's OpenSSL bindings. Some more information on the Marvin Attack can be found here: https://people.redhat.com/~hkario/marvin/
CVE-2024-4577 is under active exploitation.