[ubuntu/bionic-security] php7.2 7.2.24-0ubuntu0.18.04.7 (Accepted)
Leonidas S. Barbosa
leo.barbosa at canonical.com
Wed Oct 14 17:59:07 UTC 2020
php7.2 (7.2.24-0ubuntu0.18.04.7) bionic-security; urgency=medium
* SECURITY UPDATE: Incorrect encryption data
- debian/patches/CVE-2020-7069.patch: fix wrong ciphertext/tag
in AES-CCM encryption for a 12 bytes IV in ext/openssl/openssl.c,
ext/openssl/tests/cipher_tests.inc, ext/openssl/openssl_*_ccm.phpt.
- CVE-2020-7069
* SECURITY UPDATE: Possibly forge cookie
- debian/patches/CVE-2020-7070.patch: do not decode cookie names anymore
in main/php_variables.c, tests/basic/022.phpt, tests/basic/023.phpt,
tests/basic/bug79699.phpt.
- CVE-2020-7070
Date: 2020-10-07 18:09:13.989885+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/php7.2/7.2.24-0ubuntu0.18.04.7
-------------- next part --------------
Sorry, changesfile not available.
More information about the Bionic-changes
mailing list