Fedora 30 : php (2019-1d78e14cfd)

high Nessus Plugin ID 124476

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

**PHP version 7.3.4** (04 April 2019)

**Core:**

- Fixed bug php#77738 (Nullptr deref in zend_compile_expr). (Laruence)

- Fixed bug php#77660 (Segmentation fault on break 2147483648). (Laruence)

- Fixed bug php#77652 (Anonymous classes can lose their interface information). (Nikita)

- Fixed bug php#77345 (Stack Overflow caused by circular reference in garbage collection). (Alexandru Patranescu, Nikita, Dmitry)

- Fixed bug php#76956 (Wrong value for 'syslog.filter' documented in php.ini). (cmb)

**Apache2Handler:**

- Fixed bug php#77648 (BOM in sapi/apache2handler/php_functions.c). (cmb)

**Bcmath:**

- Fixed bug php#77742 (bcpow() implementation related to gcc compiler optimization). (Nikita)

**CLI Server:**

- Fixed bug php#77722 (Incorrect IP set to $_SERVER['REMOTE_ADDR'] on the localhost). (Nikita)

**COM:**

- Fixed bug php#77578 (Crash when php unload). (cmb)

**EXIF:**

- Fixed bug php#77753 (Heap-buffer-overflow in php_ifd_get32s). (Stas)

- Fixed bug php#77831 (Heap-buffer-overflow in exif_iif_add_value). (Stas)

**FPM:**

- Fixed bug php#77677 (FPM fails to build on AIX due to missing WCOREDUMP). (Kevin Adler)

**GD:**

- Fixed bug php#77700 (Writing truecolor images as GIF ignores interlace flag). (cmb)

**MySQLi:**

- Fixed bug php#77597 (mysqli_fetch_field hangs scripts).
(Nikita)

**Opcache:**

- Fixed bug php#77743 (Incorrect pi node insertion for jmpznz with identical successors). (Nikita)

**Phar:**

- Fxied bug php#77697 (Crash on Big_Endian platform).
(Laruence)

**phpdbg:**

- Fixed bug php#77767 (phpdbg break cmd aliases listed in help do not match actual aliases). (Miriam Lauter)

**sodium:**

- Fixed bug php#77646 (sign_detached() strings not terminated). (Frank)

**SQLite3:**

- Added sqlite3.defensive INI directive. (BohwaZ)

**Standard:**

- Fixed bug php#77664 (Segmentation fault when using undefined constant in custom wrapper). (Laruence)

- Fixed bug php#77669 (Crash in extract() when overwriting extracted array). (Nikita)

- Fixed bug php#76717 (var_export() does not create a parsable value for PHP_INT_MIN). (Nikita)

- Fixed bug php#77765 (FTP stream wrapper should set the directory as executable). (Vlad Temian)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected php package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2019-1d78e14cfd

Plugin Details

Severity: High

ID: 124476

File Name: fedora_2019-1d78e14cfd.nasl

Version: 1.2

Type: local

Agent: unix

Published: 5/2/2019

Updated: 9/23/2019

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php, cpe:/o:fedoraproject:fedora:30

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 4/7/2019

Vulnerability Publication Date: 4/7/2019

Reference Information