FEDORA-2023-1aa721a7bb
Packages in this update:
php-8.2.9-1.fc38
Update description:
PHP version 8.2.9 (03 Aug 2023)
Build:
Fixed bug GH-11522 (PHP version check fails with ‘-‘ separator). (SVGAnimate)
CLI:
Fix interrupted CLI output causing the process to exit. (nielsdos)
Core:
Fixed oss-fuzz php#60011 (Mis-compilation of by-reference nullsafe operator). (ilutov)
Fixed line number of JMP instruction over else block. (ilutov)
Fixed use-of-uninitialized-value with ??= on assert. (ilutov)
Fixed oss-fuzz php#60411 (Fix double-compilation of arrow-functions). (ilutov)
Fixed build for FreeBSD before the 11.0 releases. (David Carlier)
Curl:
Fix crash when an invalid callback function is passed to CURLMOPT_PUSHFUNCTION. (nielsdos)
Date:
Fixed bug GH-11368 (Date modify returns invalid datetime). (Derick)
Fixed bug GH-11600 (Can’t parse time strings which include (narrow) non-breaking space characters). (Derick)
DOM:
Fixed bug GH-11625 (DOMElement::replaceWith() doesn’t replace node with DOMDocumentFragment but just deletes node or causes wrapping <> depending on libxml2 version). (nielsdos)
Fileinfo:
Fixed bug GH-11298 (finfo returns wrong mime type for xz files). (Anatol)
FTP:
Fix context option check for “overwrite”. (JonasQuinten)
Fixed bug GH-10562 (Memory leak and invalid state with consecutive ftp_nb_fget). (nielsdos)
GD:
Fix most of the external libgd test failures. (Michael Orlitzky)
Intl:
Fix memory leak in MessageFormatter::format() on failure. (Girgias) Libxml:
Fixed bug GHSA-3qrf-m4j2-pcrr (Security issue with external entity loading in XML without enabling it). (CVE-2023-3823) (nielsdos, ilutov)
MBString:
Fix GH-11300 (license issue: restricted unicode license headers). (nielsdos)
Opcache:
Fixed bug GH-10914 (OPCache with Enum and Callback functions results in segmentation fault). (nielsdos)
Prevent potential deadlock if accelerated globals cannot be allocated. (nielsdos)
PCNTL:
Fixed bug GH-11498 (SIGCHLD is not always returned from proc_open). (nielsdos)
PDO:
Fix GH-11587 (After php8.1, when PDO::ATTR_EMULATE_PREPARES is true and PDO::ATTR_STRINGIFY_FETCHES is true, decimal zeros are no longer filled). (SakiTakamachi)
PDO SQLite:
Fix GH-11492 (Make test failure: ext/pdo_sqlite/tests/bug_42589.phpt). (KapitanOczywisty, CViniciusSDias)
Phar:
Add missing check on EVP_VerifyUpdate() in phar util. (nielsdos)
Fixed bug GHSA-jqcx-ccgc-xwhv (Buffer mismanagement in phar_dir_read()). (CVE-2023-3824) (nielsdos)
PHPDBG:
Fixed bug GH-9669 (phpdbg -h options doesn’t list the -z option). (adsr)
Session:
Removed broken url support for transferring session ID. (ilutov)
Standard:
Fix serialization of RC1 objects appearing in object graph twice. (ilutov) Streams:
Fixed bug GH-11735 (Use-after-free when unregistering user stream wrapper from itself). (ilutov)
SQLite3:
Fix replaced error handling in SQLite3Stmt::__construct. (nielsdos)
XMLReader:
Fix GH-11548 (Argument corruption when calling XMLReader::open or XMLReader::XML non-statically with observer active). (Bob)
More Stories
openjpeg2-2.5.3-1.fc40
FEDORA-2024-272544ceb9 Packages in this update: openjpeg2-2.5.3-1.fc40 Update description: Update to openjpeg-2.5.3 Fix 2 heap-buffer-overflow Read More
libxml2-2.12.9-1.fc40
FEDORA-2024-9f3765a04b Packages in this update: libxml2-2.12.9-1.fc40 Update description: Update to 2.12.9 Fixes CVE-2024-40896 Read More
libxml2-2.12.9-1.fc41
FEDORA-2024-867a14de12 Packages in this update: libxml2-2.12.9-1.fc41 Update description: Update to 2.12.9 Fixes CVE-2024-40896. Read More
iwd-3.3-1.fc40 libell-0.71-1.fc40
FEDORA-2024-0fa283c43a Packages in this update: iwd-3.3-1.fc40 libell-0.71-1.fc40 Update description: iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix...
iwd-3.3-1.fc41 libell-0.71-1.fc41
FEDORA-2024-256818da09 Packages in this update: iwd-3.3-1.fc41 libell-0.71-1.fc41 Update description: iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix...
A Vulnerability in Apache Struts2 Could Allow for Remote Code Execution
A vulnerability has been discovered in Apache Struts2, which could allow for remote code execution. Apache Struts2 is an open-source...