Revisions of php7

Petr Gajdos's avatar Petr Gajdos (pgajdos) committed (revision 9)
- security update
- added patches
  fix CVE-2023-3823 [bsc#1214106], XML loading external entity without being enabled
  + php7-CVE-2023-3823.patch
  fix CVE-2023-3824 [bsc#1214103], buffer overflows in phar_dir_read()
  + php7-CVE-2023-3824.patch
Petr Gajdos's avatar Petr Gajdos (pgajdos) committed (revision 8)
- security update
- added patches
  fix CVE-2023-3247 [bsc#1212349], Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP
  + php7-CVE-2023-3247.patch
Arjen de Korte's avatar Arjen de Korte (adkorte) committed (revision 7)
- The %_restart_on_update macro was removed from systemd-rpm-macros.
  Remove %posttrans for FPM as it wasn't working as intended anyway.
  [boo#1210576]
Petr Gajdos's avatar Petr Gajdos (pgajdos) committed (revision 6)
- modified patches
  fix potential buffer overflow [bsc#1208199]
  % php-systzdata-v19.patch (refreshed)
- added patches
  fix CVE-2023-0568 [bsc#1208366], NULL byte off-by-one in php_check_specific_open_basedir
  + php7-CVE-2023-0568.patch
Petr Gajdos's avatar Petr Gajdos (pgajdos) accepted request 1066278 from Arjen de Korte's avatar Arjen de Korte (adkorte) (revision 5)
- security update
- added patches
  fix CVE-2023-0567 (Password_verify() always return true with some hash)
  + php7-CVE-2023-0567-a.patch and php7-CVE-2023-0567-b.patch
  fix CVE-2023-0568 (1-byte array overrun in common path resolve code)
  + php7-CVE-2023-0568.patch
  fix CVE-2023-0662 (DOS vulnerability when parsing multipart request body)
  + php7-CVE-2023-0662.patch
Petr Gajdos's avatar Petr Gajdos (pgajdos) accepted request 1057134 from Paolo Panto's avatar Paolo Panto (munix9) (revision 4)
- Add fix-NETSNMP_DISABLE_DES.patch to solve
  "error: 'usmDESPrivProtocol' undeclared" on Factory/TW
Petr Gajdos's avatar Petr Gajdos (pgajdos) committed (revision 3)
Petr Gajdos's avatar Petr Gajdos (pgajdos) committed (revision 2)
- security update
- added patches
  fix CVE-2022-31631 [bsc#1206958], Due to an integer overflow PDO:quote() may return unquoted string
  + php7-CVE-2022-31631.patch
Petr Gajdos's avatar Petr Gajdos (pgajdos) committed (revision 1)
osc copypac from project:openSUSE:Factory package:php7 revision:119
Displaying all 9 revisions
openSUSE Build Service is sponsored by