Fedora Linux 8725 Published by

Fedora Linux has received security updates, including php-8.3.12-1.fc40, cjson-1.7.18-1.fc41, and php-8.3.12-1.fc41:

[SECURITY] Fedora 40 Update: php-8.3.12-1.fc40
[SECURITY] Fedora 41 Update: cjson-1.7.18-1.fc41
[SECURITY] Fedora 41 Update: php-8.3.12-1.fc41




[SECURITY] Fedora 40 Update: php-8.3.12-1.fc40


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-2b429e720e
2024-10-02 02:58:10.993110
--------------------------------------------------------------------------------

Name : php
Product : Fedora 40
Version : 8.3.12
Release : 1.fc40
URL : http://www.php.net/
Summary : PHP scripting language for creating dynamic web sites
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.

--------------------------------------------------------------------------------
Update Information:

PHP version 8.3.12 (26 Sep 2024)
CGI:
Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection
Vulnerability). (CVE-2024-8926) (nielsdos)
Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable
due to the environment variable collision). (CVE-2024-8927) (nielsdos)
Core:
Fixed bug GH-15408 (MSan false-positve on zend_max_execution_timer). (zeriyoshi)
Fixed bug GH-15515 (Configure error grep illegal option q). (Peter Kokot)
Fixed bug GH-15514 (Configure error: genif.sh: syntax error). (Peter Kokot)
Fixed bug GH-15565 (--disable-ipv6 during compilation produces error EAI_SYSTEM
not found). (nielsdos)
Fixed bug GH-15587 (CRC32 API build error on arm 32-bit). (Bernd Kuhls, Thomas
Petazzoni)
Fixed bug GH-15330 (Do not scan generator frames more than once). (Arnaud)
Fixed uninitialized lineno in constant AST of internal enums. (ilutov)
Curl:
FIxed bug GH-15547 (curl_multi_select overflow on timeout argument). (David
Carlier)
DOM:
Fixed bug GH-15551 (Segmentation fault (access null pointer) in
ext/dom/xml_common.h). (nielsdos)
Fixed bug GH-15654 (Signed integer overflow in ext/dom/nodelist.c). (nielsdos)
Fileinfo:
Fixed bug GH-15752 (Incorrect error message for finfo_file with an empty
filename argument). (DanielEScherzer)
FPM:
Fixed bug GHSA-865w-9rf3-2wh5 (Logs from childrens may be altered).
(CVE-2024-9026) (Jakub Zelenka)
MySQLnd:
Fixed bug GH-15432 (Heap corruption when querying a vector). (cmb, Kamil
Tekiela)
Opcache:
Fixed bug GH-15661 (Access null pointer in Zend/Optimizer/zend_inference.c).
(nielsdos)
Fixed bug GH-15658 (Segmentation fault in Zend/zend_vm_execute.h). (nielsdos)
SAPI:
Fixed bug GHSA-9pqp-7h25-4f32 (Erroneous parsing of multipart form data).
(CVE-2024-8925) (Arnaud)
Standard:
Fixed bug GH-15552 (Signed integer overflow in ext/standard/scanf.c). (cmb)
Streams:
Fixed bug GH-15628 (php_stream_memory_get_buffer() not zero-terminated). (cmb)
--------------------------------------------------------------------------------
ChangeLog:

* Wed Sep 25 2024 Remi Collet [remi@remirepo.net] - 8.3.12-1
- Update to 8.3.12 - http://www.php.net/releases/8_3_12.php
- enable command history in phpdbg
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-2b429e720e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 41 Update: cjson-1.7.18-1.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-82f3634c69
2024-10-02 01:30:51.688935
--------------------------------------------------------------------------------

Name : cjson
Product : Fedora 41
Version : 1.7.18
Release : 1.fc41
URL : https://github.com/DaveGamble/cJSON
Summary : Ultralightweight JSON parser in ANSI C
Description :
cJSON aims to be the dumbest possible parser that you can get your job
done with. It's a single file of C, and a single header file.

--------------------------------------------------------------------------------
Update Information:

Update to new upstream version (closes rhbz#2237124)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Sep 26 2024 Fabian Affolter - 1.7.18-1
- Update to new upstream version (closes rhbz#2237124)
- Fix rhbz#2277268, closes rhbz#2277269
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2277268 - CVE-2024-31755 cjson: segmentation violation trigger through the second parameter of function cJSON_SetValuestring at cJSON.c
https://bugzilla.redhat.com/show_bug.cgi?id=2277268
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-82f3634c69' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 41 Update: php-8.3.12-1.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-a03b06dbd0
2024-10-02 01:30:51.688919
--------------------------------------------------------------------------------

Name : php
Product : Fedora 41
Version : 8.3.12
Release : 1.fc41
URL : http://www.php.net/
Summary : PHP scripting language for creating dynamic web sites
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.

--------------------------------------------------------------------------------
Update Information:

PHP version 8.3.12 (26 Sep 2024)
CGI:
Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection
Vulnerability). (CVE-2024-8926) (nielsdos)
Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable
due to the environment variable collision). (CVE-2024-8927) (nielsdos)
Core:
Fixed bug GH-15408 (MSan false-positve on zend_max_execution_timer). (zeriyoshi)
Fixed bug GH-15515 (Configure error grep illegal option q). (Peter Kokot)
Fixed bug GH-15514 (Configure error: genif.sh: syntax error). (Peter Kokot)
Fixed bug GH-15565 (--disable-ipv6 during compilation produces error EAI_SYSTEM
not found). (nielsdos)
Fixed bug GH-15587 (CRC32 API build error on arm 32-bit). (Bernd Kuhls, Thomas
Petazzoni)
Fixed bug GH-15330 (Do not scan generator frames more than once). (Arnaud)
Fixed uninitialized lineno in constant AST of internal enums. (ilutov)
Curl:
FIxed bug GH-15547 (curl_multi_select overflow on timeout argument). (David
Carlier)
DOM:
Fixed bug GH-15551 (Segmentation fault (access null pointer) in
ext/dom/xml_common.h). (nielsdos)
Fixed bug GH-15654 (Signed integer overflow in ext/dom/nodelist.c). (nielsdos)
Fileinfo:
Fixed bug GH-15752 (Incorrect error message for finfo_file with an empty
filename argument). (DanielEScherzer)
FPM:
Fixed bug GHSA-865w-9rf3-2wh5 (Logs from childrens may be altered).
(CVE-2024-9026) (Jakub Zelenka)
MySQLnd:
Fixed bug GH-15432 (Heap corruption when querying a vector). (cmb, Kamil
Tekiela)
Opcache:
Fixed bug GH-15661 (Access null pointer in Zend/Optimizer/zend_inference.c).
(nielsdos)
Fixed bug GH-15658 (Segmentation fault in Zend/zend_vm_execute.h). (nielsdos)
SAPI:
Fixed bug GHSA-9pqp-7h25-4f32 (Erroneous parsing of multipart form data).
(CVE-2024-8925) (Arnaud)
Standard:
Fixed bug GH-15552 (Signed integer overflow in ext/standard/scanf.c). (cmb)
Streams:
Fixed bug GH-15628 (php_stream_memory_get_buffer() not zero-terminated). (cmb)
--------------------------------------------------------------------------------
ChangeLog:

* Wed Sep 25 2024 Remi Collet [remi@remirepo.net] - 8.3.12-1
- Update to 8.3.12 - http://www.php.net/releases/8_3_12.php
* Wed Sep 11 2024 Remi Collet [remi@remirepo.net] - 8.3.12~RC1-2
- enable command history in phpdbg
* Tue Sep 10 2024 Remi Collet [remi@remirepo.net] - 8.3.12~RC1-1
- update to 8.3.12RC1
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-a03b06dbd0' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--