MGASA-2019-0253
Dashboard / Vulnerabilities / MGASA-2019-0253
MGASA-2019-0253
Summary: Updated php packages fix security vulnerabilities
Details: Updated php packages fix security vulnerabilities: A use-after-free in onig_new_deluxe() in regext.c in the bundled Oniguruma allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression (CVE-2019-13224). A NULL Pointer Dereference in match_at() in regexec.c in the bundled Oniguruma allows attackers to potentially cause denial of service by providing a crafted regular expression (CVE-2019-13225). For other fixes in this update, see the referenced changelog.
References: https://advisories.mageia.org/MGASA-2019-0253.html, https://bugs.mageia.org/show_bug.cgi?id=25380, https://www.php.net/ChangeLog-7.php#PHP_7_3_9
Affected packages
Package
Name: php
Purl: pkg:rpm/mageia/php?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
