Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 799776 (CVE-2021-21704, CVE-2021-21705)

Summary: <dev-lang/php-{7.3.29,7.4.21,8.0.8}: multiple vulnerabilities (CVE-2021-21704, CVE-2021-21705)
Product: Gentoo Security Reporter: Michael Orlitzky <mjo>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: php-bugs
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [glsa+]
Package list:
dev-lang/php-7.3.29 dev-lang/php-7.4.21-r1
Runtime testing required: ---

Description Michael Orlitzky gentoo-dev 2021-07-01 22:21:37 UTC
The three latest PHP releases all fix security issues in earlier versions:

* https://www.php.net/ChangeLog-7.php#7.3.29
* https://www.php.net/ChangeLog-7.php#7.4.21
* https://www.php.net/ChangeLog-8.php#8.0.8

I've already cleaned up the unstable 8.x ebuilds, but the 7.x versions need stabilization. @php-bugs, any objections?
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-07-01 22:26:11 UTC
Thank you!
Comment 2 Rolf Eike Beer archtester 2021-07-07 14:52:18 UTC
sparc stable
Comment 3 Agostino Sarubbo gentoo-dev 2021-07-08 06:21:36 UTC
ppc stable
Comment 4 Agostino Sarubbo gentoo-dev 2021-07-08 06:22:10 UTC
ppc64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2021-07-09 06:26:54 UTC
amd64 stable
Comment 6 NATTkA bot gentoo-dev 2021-07-10 18:56:26 UTC Comment hidden (obsolete)
Comment 7 Agostino Sarubbo gentoo-dev 2021-07-13 06:34:16 UTC
x86 stable
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-07-17 04:59:31 UTC
arm done
Comment 9 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-07-20 01:27:14 UTC
arm64 done

all arches done
Comment 10 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-07-20 02:06:06 UTC
Please cleanup, thanks!
Comment 11 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-07 17:15:38 UTC
Ping
Comment 12 Larry the Git Cow gentoo-dev 2021-08-07 18:53:19 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8de490e5bdeaef1f24a582a397d962d009da0a97

commit 8de490e5bdeaef1f24a582a397d962d009da0a97
Author:     Michael Orlitzky <mjo@gentoo.org>
AuthorDate: 2021-08-07 18:51:25 +0000
Commit:     Michael Orlitzky <mjo@gentoo.org>
CommitDate: 2021-08-07 18:51:49 +0000

    dev-lang/php: cleanup after CVE-2021-21704 and CVE-2021-21705.
    
    Bug: https://bugs.gentoo.org/799776
    Package-Manager: Portage-3.0.20, Repoman-3.0.2
    Signed-off-by: Michael Orlitzky <mjo@gentoo.org>

 dev-lang/php/Manifest             |   2 -
 dev-lang/php/php-7.3.28.ebuild    | 758 --------------------------------------
 dev-lang/php/php-7.4.19-r1.ebuild | 750 -------------------------------------
 3 files changed, 1510 deletions(-)
Comment 13 NATTkA bot gentoo-dev 2021-10-06 02:44:33 UTC
Unable to check for sanity:

> no match for package: dev-lang/php-7.3.29
Comment 14 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-26 14:23:12 UTC
GLSA request filed
Comment 15 Larry the Git Cow gentoo-dev 2022-09-29 14:48:15 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=4447c90f117a8f0928cc5e880f3cfc9fde7ee918

commit 4447c90f117a8f0928cc5e880f3cfc9fde7ee918
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2022-09-29 14:23:13 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2022-09-29 14:48:00 +0000

    [ GLSA 202209-20 ] PHP: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/799776
    Bug: https://bugs.gentoo.org/810526
    Bug: https://bugs.gentoo.org/819510
    Bug: https://bugs.gentoo.org/833585
    Bug: https://bugs.gentoo.org/850772
    Bug: https://bugs.gentoo.org/857054
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 glsa-202209-20.xml | 71 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 71 insertions(+)
Comment 16 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-29 14:52:09 UTC
GLSA released, all done!