Fedora Linux 8579 Published by

A php security update has been released for Fedora 37.



[SECURITY] Fedora 37 Update: php-8.1.22-1.fc37


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2023-c68f2227e6
2023-08-11 00:57:19.837882
--------------------------------------------------------------------------------

Name : php
Product : Fedora 37
Version : 8.1.22
Release : 1.fc37
URL : http://www.php.net/
Summary : PHP scripting language for creating dynamic web sites
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.

--------------------------------------------------------------------------------
Update Information:

**PHP version 8.1.22** (03 Aug 2023) **Build:** * Fixed bug
[GH-11522]( https://github.com/php/php-src/issues/11522) (PHP version check fails
with '-' separator). (SVGAnimate) **CLI:** * Fix interrupted CLI output
causing the process to exit. (nielsdos) **Core:** * Fixed oss-fuzz php#60011
(Mis-compilation of by-reference nullsafe operator). (ilutov) * Fixed use-of-
uninitialized-value with ??= on assert. (ilutov) * Fixed build for FreeBSD
before the 11.0 releases. (David Carlier) **Curl:** * Fix crash when an
invalid callback function is passed to CURLMOPT_PUSHFUNCTION. (nielsdos)
**Date:** * Fixed bug [GH-11368]( https://github.com/php/php-src/issues/11368)
(Date modify returns invalid datetime). (Derick) **DOM:** * Fixed bug
[GH-11625]( https://github.com/php/php-src/issues/11625)
(DOMElement::replaceWith() doesn't replace node with DOMDocumentFragment but
just deletes node or causes wrapping depending on libxml2 version).
(nielsdos) **Fileinfo:** * Fixed bug [GH-11298]( https://github.com/php/php-
src/issues/11298) (finfo returns wrong mime type for xz files). (Anatol)
**FTP:** * Fix context option check for "overwrite". (JonasQuinten) * Fixed bug
[GH-10562]( https://github.com/php/php-src/issues/10562) (Memory leak and invalid
state with consecutive ftp_nb_fget). (nielsdos) **GD:** * Fix most of the
external libgd test failures. (Michael Orlitzky) **Hash:** * Fix use-of-
uninitialized-value in hash_pbkdf2(), fix missing $options parameter in
signature. (ilutov) **Intl:** * Fix memory leak in MessageFormatter::format()
on failure. (Girgias) **Libxml:** * Fixed bug
[GHSA-3qrf-m4j2-pcrr]( https://github.com/php/php-
src/security/advisories/GHSA-3qrf-m4j2-pcrr) (Security issue with external
entity loading in XML without enabling it). (**CVE-2023-3823**) (nielsdos,
ilutov) **MBString:** * Fix [GH-11300]( https://github.com/php/php-
src/issues/11300) (license issue: restricted unicode license headers).
(nielsdos) **Opcache:** * Fixed bug [GH-10914]( https://github.com/php/php-
src/issues/10914) (OPCache with Enum and Callback functions results in
segmentation fault). (nielsdos) * Prevent potential deadlock if accelerated
globals cannot be allocated. (nielsdos) **PCNTL:** * Fixed bug
[GH-11498]( https://github.com/php/php-src/issues/11498) (SIGCHLD is not always
returned from proc_open). (nielsdos) **PCRE:** * Mangle PCRE regex cache key
with JIT option. (mvorisek) **PDO:** * Fix
[GH-11587]( https://github.com/php/php-src/issues/11587) (After php8.1, when
PDO::ATTR_EMULATE_PREPARES is true and PDO::ATTR_STRINGIFY_FETCHES is true,
decimal zeros are no longer filled). (SakiTakamachi) **PDO SQLite:** * Fix
[GH-11492]( https://github.com/php/php-src/issues/11492) (Make test failure:
ext/pdo_sqlite/tests/bug_42589.phpt). (KapitanOczywisty, CViniciusSDias)
**Phar:** * Add missing check on EVP_VerifyUpdate() in phar util. (nielsdos) *
Fixed bug [GHSA-jqcx-ccgc-xwhv]( https://github.com/php/php-
src/security/advisories/GHSA-jqcx-ccgc-xwhv) (Buffer mismanagement in
phar_dir_read()). (**CVE-2023-3824**) (nielsdos) **PHPDBG:** * Fixed bug
[GH-9669]( https://github.com/php/php-src/issues/9669) (phpdbg -h options doesn't
list the -z option). (adsr) **Session:** * Removed broken url support for
transferring session ID. (ilutov) **Standard:** * Fix serialization of RC1
objects appearing in object graph twice. (ilutov) **SQLite3:** * Fix replaced
error handling in SQLite3Stmt::__construct. (nielsdos)
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 2 2023 Remi Collet [remi@remirepo.net] - 8.1.22-1
- Update to 8.1.22 - http://www.php.net/releases/8_1_22.php
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-c68f2227e6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------