From ${URL} : Hi, the changelog for PHP 5.6.14 and 5.5.30 lists these two issues that have a security impact: Null pointer dereference in phar_get_fp_offset() https://bugs.php.net/bug.php?id=69720 Uninitialized pointer in phar_make_dirstream when zip entry filename is "/" https://bugs.php.net/bug.php?id=70433 Both result in a crash @maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Arches, please test and mark stable: =dev-lang/php-5.5.30 =dev-lang/php-5.6.14 Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 sparc x86"
amd64 stable
x86 stable
Stable for PPC64.
Stable for HPPA.
Stable on alpha.
ppc stable
sparc stable
arm stable
ia64 stable
I've removed the affected versions, php-5.5.29 and php-5.6.13.
Arches and Maintainer(s), Thank you for your work. Added to an existing GLSA Request.
This issue was resolved and addressed in GLSA 201606-10 at https://security.gentoo.org/glsa/201606-10 by GLSA coordinator Kristian Fiskerstrand (K_F).