gpp_maybe
Security update for php7
SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1025
This update for php7 fixes the following issues: - CVE-2024-11235: Fixed reference counting in php_request_shutdown causing Use-After-Free (bsc#1239666) - CVE-2025-1217: Fixed header parser of http stream wrapper not handling folded headers (bsc#1239664) - CVE-2025-1219: Fixed libxml streams using wrong content-type header when requesting a redirected resource (bsc#1239667) - CVE-2025-1734: Fixed streams HTTP wrapper not failing for headers with invalid name and no colon (bsc#1239668) - CVE-2025-1736: Fixed stream HTTP wrapper header check might omitting basic auth header (bsc#1239670) - CVE-2025-1861: Fixed stream HTTP wrapper truncate redirect location to 1024 bytes (bsc#1239669)
-
Release DateMar 26 2025
-
ReferencesBugzilla: 1239669, 1239666, 1239667, 1239668, 1239670, 1239664
CVEs: CVE-2025-1861, CVE-2025-1736, CVE-2025-1219, CVE-2024-11235, CVE-2025-1734, CVE-2025-1217 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Package Hub 15.6 s390x
-
Packages
SUSE Package Hub 15.6 aarch64
-
Packages
SUSE Package Hub 15.6 ppc64le
-
Packages
SUSE Package Hub 15.6 x86_64
-
Packages