Opened 3 days ago
Closed 2 days ago
#21240 closed enhancement (fixed)
php-8.4.5
Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
---|---|---|---|
Priority: | elevated | Milestone: | 12.4 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New point version.
Change History (5)
comment:1 by , 3 days ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:3 by , 2 days ago
CVE-2024-11235: Moderate - Reference counting in php_request_shutdown causes Use-After-Free (https://github.com/php/php-src/security/advisories/GHSA-rwp7-7vc6-8477)
(No CVE Assigned): Low, Possible out of bounds read when XML_OPTION_SKIP_TAGSTART used (https://github.com/php/php-src/security/advisories/GHSA-wg4p-4hqh-c3g9)
CVE-2025-1219: Moderate, libxml streams use wrong content-type
header when requesting a redirected resource (https://github.com/php/php-src/security/advisories/GHSA-p3x9-6h7p-cgfc)
CVE-2025-1736: Moderate, Stream HTTP wrapper header check might omit basic auth header (https://github.com/php/php-src/security/advisories/GHSA-hgf5-96fm-v528)
CVE-2025-1861: Moderate, Stream HTTP wrapper truncate redirect location to 1024 bytes (https://github.com/php/php-src/security/advisories/GHSA-52jp-hrpf-2jff)
CVE-2025-1734: Moderate, Streams HTTP wrapper does not fail for headers with invalid name and no colon (https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36c-qc44)
CVE-2025-1217: Moderate, Header parser of http
stream wrapper does not handle folded headers (https://github.com/php/php-src/security/advisories/GHSA-v8xr-gpvj-cx9g)
comment:4 by , 2 days ago
Priority: | normal → elevated |
---|
comment:5 by , 2 days ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Fixed at d078e43016fd74ebacdb46369e53e6fa5632d7d4
SA-12.3-005 issued