Path to this page:
Subject: CVS commit: [pkgsrc-2021Q2] pkgsrc/lang
From: Benny Siegert
Date: 2021-07-04 21:31:01
Message id: 20210704193102.605FAFA90@cvs.NetBSD.org
Log Message:
Pullup ticket #6479 - requested by taca
lang/php80: security fix
Revisions pulled up:
- lang/php/phpversion.mk 1.332
- lang/php80/distinfo 1.5
---
Module Name: pkgsrc
Committed By: taca
Date: Fri Jul 2 17:30:35 UTC 2021
Modified Files:
pkgsrc/lang/php: phpversion.mk
pkgsrc/lang/php80: distinfo
Log Message:
lang/php80: update to 8.0.8
01 Jul 2021, PHP 8.0.8
- Core:
. Fixed bug #81076 (incorrect debug info on Closures with implicit bi=
nds).
(krakjoe)
. Fixed bug #81068 (Double free in realpath_cache_clean()). (Dimitry =
Andric)
. Fixed bug #76359 (open_basedir bypass through adding ".."). (cmb)
. Fixed bug #81090 (Typed property performance degradation with .=3D =
operator).
(Nikita)
. Fixed bug #81070 (Integer underflow in memory limit comparison).
(Peter van Dommelen)
. Fixed bug #81122 (SSRF bypass in FILTER_VALIDATE_URL).
(CVE-2021-21705) (cmb)
- Bzip2:
. Fixed bug #81092 (fflush before stream_filter_remove corrupts strea=
m).
(cmb)
- Fileinfo:
. Fixed bug #80197 (implicit declaration of function 'magic_stream' i=
s
invalid). (Nikita)
- GMP:
. Fixed bug #81119 (GMP operators throw errors with wrong parameter n=
ames).
(Nikita)
- OCI8:
. Fixed bug #81088 (error in regression test for oci_fetch_object() a=
nd
oci_fetch_array()). (M=E1t=E9)
- Opcache:
. Fixed bug #81051 (Broken property type handling after incrementing
reference). (Dmitry)
. Fixed bug #80968 (JIT segfault with return from required file). (Dm=
itry)
- OpenSSL:
. Fixed bug #76694 (native Windows cert verification uses CN as sever=
name).
(cmb)
- MySQLnd:
. Fixed bug #80761 (PDO uses too much memory). (Nikita)
- PDO_Firebird:
. Fixed bug #76448 (Stack buffer overflow in firebird_info_cb).
(CVE-2021-21704) (cmb)
. Fixed bug #76449 (SIGSEGV in firebird_handle_doer).
(CVE-2021-21704) (cmb)
. Fixed bug #76450 (SIGSEGV in firebird_stmt_execute).
(CVE-2021-21704) (cmb)
. Fixed bug #76452 (Crash while parsing blob data in firebird_fetch_=
blob).
(CVE-2021-21704) (cmb)
- readline:
. Fixed bug #72998 (invalid read in readline completion). (krakjoe)
- Standard:
. Fixed bug #81048 (phpinfo(INFO_VARIABLES) "Array to string conversi=
on").
(cmb)
. Fixed bug #77627 (method_exists on Closure::__invoke inconsistency)=
.=
(krakjoe)
- Windows:
. Fixed bug #81120 (PGO data for main PHP DLL are not used). (cmb)
Files: