Path to this page:
Subject: CVS commit: [pkgsrc-2021Q2] pkgsrc/lang
From: Benny Siegert
Date: 2021-07-04 21:16:05
Message id: 20210704191606.08540FA90@cvs.NetBSD.org
Log Message:
Pullup ticket #6478 - requested by taca
lang/php74: security fix
Revisions pulled up:
- lang/php/phpversion.mk 1.331
- lang/php74/distinfo 1.25
---
Module Name: pkgsrc
Committed By: taca
Date: Fri Jul 2 17:28:28 UTC 2021
Modified Files:
pkgsrc/lang/php: phpversion.mk
pkgsrc/lang/php74: distinfo
Log Message:
lang/php74: update to 7.4.21
01 Jul 2021, PHP 7.4.21
- Core:
. Fixed bug #81068 (Double free in realpath_cache_clean()). (Dimitry Andric)
. Fixed bug #76359 (open_basedir bypass through adding ".."). (cmb)
. Fixed bug #81090 (Typed property performance degradation with .= operator).
(Nikita)
. Fixed bug #81070 (Integer underflow in memory limit comparison).
(Peter van Dommelen)
. Fixed bug #81122 (SSRF bypass in FILTER_VALIDATE_URL).
(CVE-2021-21705) (cmb)
- Bzip2:
. Fixed bug #81092 (fflush before stream_filter_remove corrupts stream).
(cmb)
- OpenSSL:
. Fixed bug #76694 (native Windows cert verification uses CN as sever name).
(cmb)
- PDO_Firebird:
. Fixed bug #76448 (Stack buffer overflow in firebird_info_cb).
(CVE-2021-21704) (cmb)
. Fixed bug #76449 (SIGSEGV in firebird_handle_doer).
(CVE-2021-21704) (cmb)
. Fixed bug #76450 (SIGSEGV in firebird_stmt_execute).
(CVE-2021-21704) (cmb)
. Fixed bug #76452 (Crash while parsing blob data in firebird_fetch_blob).
(CVE-2021-21704) (cmb)
- Standard:
. Fixed bug #81048 (phpinfo(INFO_VARIABLES) "Array to string \
conversion").
(cmb)
Files: