{
  "cves": [
    "CVE-2024-11233",
    "CVE-2024-11234",
    "CVE-2024-8929",
    "CVE-2025-1217",
    "CVE-2025-1219",
    "CVE-2025-1220",
    "CVE-2025-14177",
    "CVE-2025-14178",
    "CVE-2025-1734",
    "CVE-2025-1735",
    "CVE-2025-1736",
    "CVE-2025-1861",
    "CVE-2025-6491"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "MODERATE"
  },
  "description": "libzip\n[1.6.1-1]\n- update to 1.6.1\n- enable lzma support\n\nphp\n[7.4.33-3]\n- Fix Heap-Use-After-Free in sapi_read_post_data Processing in CLI SAPI Interface\n  GHSA-4w77-75f9-2c8w\n- Fix Configuring a proxy in a stream context might allow for CRLF injection in URIs\n  CVE-2024-11234\n- Fix Single byte overread with convert.quoted-printable-decode filter\n  CVE-2024-11233\n- Fix Leak partial content of the heap through heap buffer over-read\n  CVE-2024-8929\n- Fix libxml streams use wrong content-type header when requesting a redirected resource\n  CVE-2025-1219\n- Fix Stream HTTP wrapper header check might omit basic auth header\n  CVE-2025-1736\n- Fix Stream HTTP wrapper truncate redirect location to 1024 bytes\n  CVE-2025-1861\n- Fix Streams HTTP wrapper does not fail for headers without colon\n  CVE-2025-1734\n- Fix Header parser of http stream wrapper does not handle folded headers\n  CVE-2025-1217\n- Fix pgsql extension does not check for errors during escaping\n  CVE-2025-1735\n- Fix NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix\n  CVE-2025-6491\n- Fix Null byte termination in hostnames\n  CVE-2025-1220\n- Fix Null byte termination in dns_get_record()\n  GHSA-www2-q4fc-65wf\n- Fix Heap buffer overflow in array_merge()\n  CVE-2025-14178\n- Fix Information Leak of Memory in getimagesize\n  CVE-2025-14177\n\nphp-pear\n[1:1.10.13-1]\n- update PEAR to 1.10.13\n- update Archive_Tar to 1.4.14\n\nphp-pecl-apcu\n[5.1.18-1]\n- update to 5.1.18\n\nphp-pecl-rrd\n[2.0.1-1]\n- build for RHEL 8\n\nphp-pecl-xdebug\n[2.9.5-1]\n- update to 2.9.5\n\nphp-pecl-zip\n[1.18.2-1]\n- update to 1.18.2",
  "id": "ELSA-2026-2470",
  "ovalId": "oval:com.oracle.elsa:def:20262470",
  "source": "oracle_linux",
  "title": "ELSA-2026-2470:  php:7.4 security update (MODERATE)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-2470.html"
}