Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 722980 (CVE-2019-11048) - <dev-lang/php-{7.2.31,7.3.18,7.4.6}: Multiple vulnerabilities (CVE-2019-11048)
Summary: <dev-lang/php-{7.2.31,7.3.18,7.4.6}: Multiple vulnerabilities (CVE-2019-11048)
Status: RESOLVED FIXED
Alias: CVE-2019-11048
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://www.php.net/ChangeLog-7.php#7...
Whiteboard: B3 [noglsa cve]
Keywords: CC-ARCHES
Depends on:
Blocks:
 
Reported: 2020-05-14 09:48 UTC by Sam James
Modified: 2020-07-26 05:24 UTC (History)
2 users (show)

See Also:
Package list:
dev-lang/php-7.2.31 dev-lang/php-7.3.18 dev-lang/php-7.4.6
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-14 09:48:35 UTC
In PHP 7.4.6:

    Core:
        Fixed bug #78875 (Long variables cause OOM and temp files are not cleaned).
        Fixed bug #78876 (Long variables cause OOM and temp files are not cleaned).


In PHP 7.3.18:

    Core:
        Fixed bug #78875 (Long filenames cause OOM and temp files are not cleaned). (CVE-2019-11048)
        Fixed bug #78876 (Long variables in multipart/form-data cause OOM and temp files are not cleaned). (CVE-2019-11048)

In PHP 7.2.31:

    Core:
        Fixed bug #78875 (Long filenames cause OOM and temp files are not cleaned). (CVE-2019-11048)
        Fixed bug #78876 (Long variables in multipart/form-data cause OOM and temp files are not cleaned). (CVE-2019-11048)
Comment 1 Brian Evans (RETIRED) gentoo-dev 2020-05-14 20:00:52 UTC
Ebuilds are in the repo
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-14 21:25:02 UTC
@maintainer(s), let us know when ready for stabilisation/go ahead.
Comment 3 Agostino Sarubbo gentoo-dev 2020-05-18 12:59:08 UTC
arm stable
Comment 4 Agostino Sarubbo gentoo-dev 2020-05-18 13:00:25 UTC
ppc stable
Comment 5 Agostino Sarubbo gentoo-dev 2020-05-18 15:09:42 UTC
amd64 stable
Comment 6 Agostino Sarubbo gentoo-dev 2020-05-18 15:12:48 UTC
ppc64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2020-05-18 15:13:32 UTC
x86 stable
Comment 8 Rolf Eike Beer archtester 2020-05-18 16:55:35 UTC
sparc stable
Comment 9 Rolf Eike Beer archtester 2020-05-22 08:03:53 UTC
hppa stable
Comment 10 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-07 21:07:11 UTC
arm64 stable

----
@maintainer(s), please cleanup
Comment 11 Larry the Git Cow gentoo-dev 2020-06-10 13:53:47 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=58775a9495ead4d91391bea6edae236068f21721

commit 58775a9495ead4d91391bea6edae236068f21721
Author:     Michael Orlitzky <mjo@gentoo.org>
AuthorDate: 2020-06-10 13:52:37 +0000
Commit:     Michael Orlitzky <mjo@gentoo.org>
CommitDate: 2020-06-10 13:52:37 +0000

    dev-lang/php: remove old versions vulnerable to CVE-2019-11048.
    
    Bug: https://bugs.gentoo.org/722980
    Package-Manager: Portage-2.3.99, Repoman-2.3.22
    Signed-off-by: Michael Orlitzky <mjo@gentoo.org>

 dev-lang/php/Manifest          |   3 -
 dev-lang/php/php-7.2.30.ebuild | 755 ----------------------------------------
 dev-lang/php/php-7.3.17.ebuild | 756 -----------------------------------------
 dev-lang/php/php-7.4.5.ebuild  | 746 ----------------------------------------
 4 files changed, 2260 deletions(-)
Comment 12 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-10 14:19:02 UTC
Thanks mjo!
Comment 13 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-26 05:24:06 UTC
GLSA vote: no!

Closing.