[ubuntu/focal-security] php7.4 7.4.3-4ubuntu2.4 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Wed Oct 14 17:59:14 UTC 2020


php7.4 (7.4.3-4ubuntu2.4) focal-security; urgency=medium

  * SECURITY UPDATE: Incorrect encryption data
    - debian/patches/CVE-2020-7069.patch: fix wrong ciphertext/tag
      in AES-CCM encryption for a 12 bytes IV in ext/openssl/openssl.c,
      ext/openssl/tests/cipher_tests.inc, ext/openssl/openssl_*_ccm.phpt.
    - CVE-2020-7069
  * SECURITY UPDATE: Possibly forge cookie
    - debian/patches/CVE-2020-7070.patch: do not decode cookie names anymore
      in main/php_variables.c, tests/basic/022.phpt, tests/basic/023.phpt,
      tests/basic/bug79699.phpt.
    - CVE-2020-7070

php7.4 (7.4.3-4ubuntu2.3) focal; urgency=medium

  * d/p/0041-Fix-79019-Copied-cURL-handles-upload-empty-file.patch,
    d/p/0042-Fix-79013-Content-Length-missing-when-posting-a-curl.patch:
    Fix issue with cURL causing chunked mode for file transfers.
    (LP: #1887826)

Date: 2020-10-06 19:08:30.346689+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/php7.4/7.4.3-4ubuntu2.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list