Debian 10261 Published by

A php5 security update has been released for Debian GNU/Linux 7 Extended LTS to address a memory limit issue with long filenames or field names.



ELA-231-1 php5 security update

Package php5
Version 5.4.45-0+deb7u30
Related CVE CVE-2019-11048

When using overly long filenames or field names, a memory limit could be hit which results in stopping the upload but not cleaning up behind. This could lead to exhausted disk space on the server.

For Debian 7 Wheezy, these problems have been fixed in version 5.4.45-0+deb7u30.

We recommend that you upgrade your php5 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-231-1 php5 security update