elsa-2026-2470
oracle_linuxlibzip [1.6.1-1] - update to 1.6.1 - enable lzma support php [7.4.33-3] - Fix Heap-Use-After-Free in sapi_read_post_data Processing in CLI SAPI Interface GHSA-4w77-75f9-2c8w - Fix Configuring a proxy in a stream context might allow for CRLF injection in URIs CVE-2024-11234 - Fix Single byte overread with convert.quoted-printable-decode filter CVE-2024-11233 - Fix Leak partial content of the heap through heap buffer over-read CVE-2024-8929 - Fix libxml streams use wrong content-type header when requesting a redirected resource CVE-2025-1219 - Fix Stream HTTP wrapper header check might omit basic auth header CVE-2025-1736 - Fix Stream HTTP wrapper truncate redirect location to 1024 bytes CVE-2025-1861 - Fix Streams HTTP wrapper does not fail for headers without colon CVE-2025-1734 - Fix Header parser of http stream wrapper does not handle folded headers CVE-2025-1217 - Fix pgsql extension does not check for errors during escaping CVE-2025-1735 - Fix NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix CVE-2025-6491 - Fix Null byte termination in hostnames CVE-2025-1220 - Fix Null byte termination in dns_get_record() GHSA-www2-q4fc-65wf - Fix Heap buffer overflow in array_merge() CVE-2025-14178 - Fix Information Leak of Memory in getimagesize CVE-2025-14177 php-pear [1:1.10.13-1] - update PEAR to 1.10.13 - update Archive_Tar to 1.4.14 php-pecl-apcu [5.1.18-1] - update to 5.1.18 php-pecl-rrd [2.0.1-1] - build for RHEL 8 php-pecl-xdebug [2.9.5-1] - update to 2.9.5 php-pecl-zip [1.18.2-1] - update to 1.18.2
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2024-11233",
"CVE-2024-11234",
"CVE-2024-8929",
"CVE-2025-1217",
"CVE-2025-1219",
"CVE-2025-1220",
"CVE-2025-14177",
"CVE-2025-14178",
"CVE-2025-1734",
"CVE-2025-1735",
"CVE-2025-1736",
"CVE-2025-1861",
"CVE-2025-6491"
],
"cvss": 0.0,
"database_specific": {
"severity": "MODERATE"
},
"description": "libzip\n[1.6.1-1]\n- update to 1.6.1\n- enable lzma support\n\nphp\n[7.4.33-3]\n- Fix Heap-Use-After-Free in sapi_read_post_data Processing in CLI SAPI Interface\n GHSA-4w77-75f9-2c8w\n- Fix Configuring a proxy in a stream context might allow for CRLF injection in URIs\n CVE-2024-11234\n- Fix Single byte overread with convert.quoted-printable-decode filter\n CVE-2024-11233\n- Fix Leak partial content of the heap through heap buffer over-read\n CVE-2024-8929\n- Fix libxml streams use wrong content-type header when requesting a redirected resource\n CVE-2025-1219\n- Fix Stream HTTP wrapper header check might omit basic auth header\n CVE-2025-1736\n- Fix Stream HTTP wrapper truncate redirect location to 1024 bytes\n CVE-2025-1861\n- Fix Streams HTTP wrapper does not fail for headers without colon\n CVE-2025-1734\n- Fix Header parser of http stream wrapper does not handle folded headers\n CVE-2025-1217\n- Fix pgsql extension does not check for errors during escaping\n CVE-2025-1735\n- Fix NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix\n CVE-2025-6491\n- Fix Null byte termination in hostnames\n CVE-2025-1220\n- Fix Null byte termination in dns_get_record()\n GHSA-www2-q4fc-65wf\n- Fix Heap buffer overflow in array_merge()\n CVE-2025-14178\n- Fix Information Leak of Memory in getimagesize\n CVE-2025-14177\n\nphp-pear\n[1:1.10.13-1]\n- update PEAR to 1.10.13\n- update Archive_Tar to 1.4.14\n\nphp-pecl-apcu\n[5.1.18-1]\n- update to 5.1.18\n\nphp-pecl-rrd\n[2.0.1-1]\n- build for RHEL 8\n\nphp-pecl-xdebug\n[2.9.5-1]\n- update to 2.9.5\n\nphp-pecl-zip\n[1.18.2-1]\n- update to 1.18.2",
"id": "ELSA-2026-2470",
"ovalId": "oval:com.oracle.elsa:def:20262470",
"source": "oracle_linux",
"title": "ELSA-2026-2470: php:7.4 security update (MODERATE)",
"url": "https://linux.oracle.com/errata/ELSA-2026-2470.html"
}