Fedora 30 : php (2020-96cb012029)

high Nessus Plugin ID 135995

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

**PHP version 7.3.17** (16 Apr 2020)

**Core:**

- Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb)

- Fixed bug php#78210 (Invalid pointer address). (cmb, Nikita)

**CURL:**

- Fixed bug php#79199 (curl_copy_handle() memory leak).
(cmb)

**Date:**

- Fixed bug php#79396 (DateTime hour incorrect during DST jump forward). (Nate Brunette)

**Iconv:**

- Fixed bug php#79200 (Some iconv functions cut Windows-1258). (cmb)

**OPcache:**

- Fixed bug php#79412 (Opcache chokes and uses 100% CPU on specific script). (Dmitry)

**Session:**

- Fixed bug php#79413 (session_create_id() fails for active sessions). (cmb)

**Shmop:**

- Fixed bug php#79427 (Integer Overflow in shmop_open()).
(cmb)

**SimpleXML:**

- Fixed bug php#61597 (SXE properties may lack attributes and content). (cmb)

**Spl:**

- Fixed bug php#75673 (SplStack::unserialize() behavior).
(cmb)

- Fixed bug php#79393 (Null coalescing operator failing with SplFixedArray). (cmb)

**Standard:**

- Fixed bug php#79330 (shell_exec() silently truncates after a null byte). (stas)

- Fixed bug php#79465 (OOB Read in urldecode()). (stas)

- Fixed bug php#79410 (system() swallows last chunk if it is exactly 4095 bytes without newline). (Christian Schneider)

**Zip:**

- Fixed Bug php#79296 (ZipArchive::open fails on empty file). (Remi)

- Fixed bug php#79424 (php_zip_glob uses gl_pathc after call to globfree). (Max Rees)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected php package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2020-96cb012029

Plugin Details

Severity: High

ID: 135995

File Name: fedora_2020-96cb012029.nasl

Version: 1.1

Type: local

Agent: unix

Published: 4/27/2020

Updated: 4/27/2020

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php, cpe:/o:fedoraproject:fedora:30

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 4/25/2020

Vulnerability Publication Date: 4/25/2020

Reference Information