UbuntuUpdates.org

Package "php7.4"

Name: php7.4

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • HTML-embedded scripting language (Embedded SAPI library)
  • Bcmath module for PHP
  • bzip2 module for PHP
  • DBA module for PHP

Latest version: 7.4.9-1ubuntu1.1
Release: groovy (20.10)
Level: security
Repository: universe

Links



Other versions of "php7.4" in Groovy

Repository Area Version
base universe 7.4.9-1ubuntu1
base main 7.4.9-1ubuntu1
security main 7.4.9-1ubuntu1.1
updates universe 7.4.9-1ubuntu1.1
updates main 7.4.9-1ubuntu1.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 7.4.9-1ubuntu1.1 2020-10-27 14:07:11 UTC

  php7.4 (7.4.9-1ubuntu1.1) groovy-security; urgency=medium

  * SECURITY UPDATE: Incorrect encryption data
    - debian/patches/CVE-2020-7069.patch: fix wrong ciphertext/tag
      in AES-CCM encryption for a 12 bytes IV in ext/openssl/openssl.c,
      ext/openssl/tests/cipher_tests.inc, ext/openssl/openssl_*_ccm.phpt.
    - CVE-2020-7069
  * SECURITY UPDATE: Possibly forge cookie
    - debian/patches/CVE-2020-7070.patch: do not decode cookie names anymore
      in main/php_variables.c, tests/basic/022.phpt, tests/basic/023.phpt,
      tests/basic/bug79699.phpt.
    - CVE-2020-7070

 -- <email address hidden> (Leonidas S. Barbosa) Mon, 26 Oct 2020 12:17:14 -0300

CVE-2020-7069 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 byte
CVE-2020-7070 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names a



About   -   Send Feedback to @ubuntu_updates