{"cves":["CVE-2024-11233","CVE-2024-11234","CVE-2024-8929","CVE-2025-1217","CVE-2025-1219","CVE-2025-1220","CVE-2025-14177","CVE-2025-14178","CVE-2025-1734","CVE-2025-1735","CVE-2025-1736","CVE-2025-1861","CVE-2025-6491"],"cvss":0.0,"database_specific":{"severity":"MODERATE"},"description":"libzip\n[1.6.1-1]\n- update to 1.6.1\n- enable lzma support\n\nphp\n[7.4.33-3]\n- Fix Heap-Use-After-Free in sapi_read_post_data Processing in CLI SAPI Interface\n  GHSA-4w77-75f9-2c8w\n- Fix Configuring a proxy in a stream context might allow for CRLF injection in URIs\n  CVE-2024-11234\n- Fix Single byte overread with convert.quoted-printable-decode filter\n  CVE-2024-11233\n- Fix Leak partial content of the heap through heap buffer over-read\n  CVE-2024-8929\n- Fix libxml streams use wrong content-type header when requesting a redirected resource\n  CVE-2025-1219\n- Fix Stream HTTP wrapper header check might omit basic auth header\n  CVE-2025-1736\n- Fix Stream HTTP wrapper truncate redirect location to 1024 bytes\n  CVE-2025-1861\n- Fix Streams HTTP wrapper does not fail for headers without colon\n  CVE-2025-1734\n- Fix Header parser of http stream wrapper does not handle folded headers\n  CVE-2025-1217\n- Fix pgsql extension does not check for errors during escaping\n  CVE-2025-1735\n- Fix NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix\n  CVE-2025-6491\n- Fix Null byte termination in hostnames\n  CVE-2025-1220\n- Fix Null byte termination in dns_get_record()\n  GHSA-www2-q4fc-65wf\n- Fix Heap buffer overflow in array_merge()\n  CVE-2025-14178\n- Fix Information Leak of Memory in getimagesize\n  CVE-2025-14177\n\nphp-pear\n[1:1.10.13-1]\n- update PEAR to 1.10.13\n- update Archive_Tar to 1.4.14\n\nphp-pecl-apcu\n[5.1.18-1]\n- update to 5.1.18\n\nphp-pecl-rrd\n[2.0.1-1]\n- build for RHEL 8\n\nphp-pecl-xdebug\n[2.9.5-1]\n- update to 2.9.5\n\nphp-pecl-zip\n[1.18.2-1]\n- update to 1.18.2","id":"ELSA-2026-2470","ovalId":"oval:com.oracle.elsa:def:20262470","source":"oracle_linux","title":"ELSA-2026-2470:  php:7.4 security update (MODERATE)","url":"https://linux.oracle.com/errata/ELSA-2026-2470.html"}