51d9617474
- Fix CVE-2020-7069: In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data. - Fix CVE-2020-7070: In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. See also CVE-2020-8184 for more information. https://www.php.net/ChangeLog-7.php#7.4.11 Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by: Peter Korsgaard <peter@korsgaard.com> |
||
---|---|---|
.. | ||
0001-acinclude.m4-don-t-unset-variables.patch | ||
0002-iconv-tweak-iconv-detection.patch | ||
0003-configure-disable-the-phar-tool.patch | ||
0004-Call-apxs-with-correct-prefix.patch | ||
Config.ext | ||
Config.in | ||
php-fpm.conf | ||
php.hash | ||
php.mk |