#21820 closed enhancement (fixed)
php-8.4.10
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | elevated | Milestone: | 12.4 |
| Component: | BOOK | Version: | git |
| Severity: | normal | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 8 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 8 months ago
comment:3 by , 8 months ago
https://feedly.com/cve/CVE-2025-1735
CVE-2025-1735 is a moderate severity vulnerability in the pgsql extension that allows for SQL injection and potential crashes, affecting versions prior to 8.1.33, 8.2.29, 8.3.23, and 8.4.10. Patches are available in the aforementioned versions, which address the vulnerability. There is no information provided regarding exploitation in the wild, proof-of-concept exploits, mitigations, detections, or downstream impacts to other third-party vendors or technology
https://feedly.com/cve/CVE-2025-6491
CVE-2025-6491 is a moderate severity vulnerability involving a NULL Pointer Dereference in the SOAP extension, affecting versions prior to 8.1.33, 8.2.29, 8.3.23, and 8.4.10, with patches available in these versions. There is no information provided regarding exploitation in the wild, proof-of-concept exploits, or specific mitigations and detections. The vulnerability's impact on downstream third-party vendors or technology is not mentioned.
CVE-2025-1220 - Feedly estimated the CVSS score as HIGH. See https://www.linuxcompatible.org/story/php-8133-released/
comment:4 by , 8 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at commits
3388551c4c Update to php-8.4.10 (Security update). a392b54b2b Update to libpng-1.6.50.

03 Jul 2025, PHP 8.4.10