elsa-2026-2470

oracle_linux
Description

libzip [1.6.1-1] - update to 1.6.1 - enable lzma support php [7.4.33-3] - Fix Heap-Use-After-Free in sapi_read_post_data Processing in CLI SAPI Interface GHSA-4w77-75f9-2c8w - Fix Configuring a proxy in a stream context might allow for CRLF injection in URIs CVE-2024-11234 - Fix Single byte overread with convert.quoted-printable-decode filter CVE-2024-11233 - Fix Leak partial content of the heap through heap buffer over-read CVE-2024-8929 - Fix libxml streams use wrong content-type header when requesting a redirected resource CVE-2025-1219 - Fix Stream HTTP wrapper header check might omit basic auth header CVE-2025-1736 - Fix Stream HTTP wrapper truncate redirect location to 1024 bytes CVE-2025-1861 - Fix Streams HTTP wrapper does not fail for headers without colon CVE-2025-1734 - Fix Header parser of http stream wrapper does not handle folded headers CVE-2025-1217 - Fix pgsql extension does not check for errors during escaping CVE-2025-1735 - Fix NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix CVE-2025-6491 - Fix Null byte termination in hostnames CVE-2025-1220 - Fix Null byte termination in dns_get_record() GHSA-www2-q4fc-65wf - Fix Heap buffer overflow in array_merge() CVE-2025-14178 - Fix Information Leak of Memory in getimagesize CVE-2025-14177 php-pear [1:1.10.13-1] - update PEAR to 1.10.13 - update Archive_Tar to 1.4.14 php-pecl-apcu [5.1.18-1] - update to 5.1.18 php-pecl-rrd [2.0.1-1] - build for RHEL 8 php-pecl-xdebug [2.9.5-1] - update to 2.9.5 php-pecl-zip [1.18.2-1] - update to 1.18.2

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2024-11233",
    "CVE-2024-11234",
    "CVE-2024-8929",
    "CVE-2025-1217",
    "CVE-2025-1219",
    "CVE-2025-1220",
    "CVE-2025-14177",
    "CVE-2025-14178",
    "CVE-2025-1734",
    "CVE-2025-1735",
    "CVE-2025-1736",
    "CVE-2025-1861",
    "CVE-2025-6491"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "MODERATE"
  },
  "description": "libzip\n[1.6.1-1]\n- update to 1.6.1\n- enable lzma support\n\nphp\n[7.4.33-3]\n- Fix Heap-Use-After-Free in sapi_read_post_data Processing in CLI SAPI Interface\n  GHSA-4w77-75f9-2c8w\n- Fix Configuring a proxy in a stream context might allow for CRLF injection in URIs\n  CVE-2024-11234\n- Fix Single byte overread with convert.quoted-printable-decode filter\n  CVE-2024-11233\n- Fix Leak partial content of the heap through heap buffer over-read\n  CVE-2024-8929\n- Fix libxml streams use wrong content-type header when requesting a redirected resource\n  CVE-2025-1219\n- Fix Stream HTTP wrapper header check might omit basic auth header\n  CVE-2025-1736\n- Fix Stream HTTP wrapper truncate redirect location to 1024 bytes\n  CVE-2025-1861\n- Fix Streams HTTP wrapper does not fail for headers without colon\n  CVE-2025-1734\n- Fix Header parser of http stream wrapper does not handle folded headers\n  CVE-2025-1217\n- Fix pgsql extension does not check for errors during escaping\n  CVE-2025-1735\n- Fix NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix\n  CVE-2025-6491\n- Fix Null byte termination in hostnames\n  CVE-2025-1220\n- Fix Null byte termination in dns_get_record()\n  GHSA-www2-q4fc-65wf\n- Fix Heap buffer overflow in array_merge()\n  CVE-2025-14178\n- Fix Information Leak of Memory in getimagesize\n  CVE-2025-14177\n\nphp-pear\n[1:1.10.13-1]\n- update PEAR to 1.10.13\n- update Archive_Tar to 1.4.14\n\nphp-pecl-apcu\n[5.1.18-1]\n- update to 5.1.18\n\nphp-pecl-rrd\n[2.0.1-1]\n- build for RHEL 8\n\nphp-pecl-xdebug\n[2.9.5-1]\n- update to 2.9.5\n\nphp-pecl-zip\n[1.18.2-1]\n- update to 1.18.2",
  "id": "ELSA-2026-2470",
  "ovalId": "oval:com.oracle.elsa:def:20262470",
  "source": "oracle_linux",
  "title": "ELSA-2026-2470:  php:7.4 security update (MODERATE)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-2470.html"
}
View JSON API Download JSON