01 Oct 2020 Core: Fixed #79699 (PHP parses encoded cookie names so malicious `__Host-` cookies can be sent). (CVE-2020-7070) OpenSSL: Fixed #79601 (Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV). (CVE-2020-7069)
Please bump to 7.2.34, 7.3.23, 7.4.11.
arm done
hppa/sparc stable
arm64 done
amd64 stable
ppc stable
ppc64 stable
x86 stable. Maintainer(s), please cleanup. Security, please vote.
Unable to check for sanity: > no match for package: dev-lang/php-7.3.23
Unable to check for sanity: > no match for package: dev-lang/php-7.2.34
Added to an existing GLSA request.
This issue was resolved and addressed in GLSA 202012-16 at https://security.gentoo.org/glsa/202012-16 by GLSA coordinator Thomas Deutschmann (whissi).