{"id":"MGASA-2014-0542","summary":"Updated php packages fix CVE-2014-8142","details":"Updated php packages fix security vulnerability:\n\nA use-after-free flaw was found in PHP unserialize().  An untrusted input\ncould cause PHP interpreter to crash or, possibly, execute arbitrary code\nwhen processed using unserialize() (CVE-2014-8142).\n\nPHP has been updated to version 5.5.20, which fixes these issues and other\nbugs.\n","modified":"2026-04-16T06:24:57.762943557Z","published":"2014-12-21T20:47:32Z","upstream":["CVE-2014-8142"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0542.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14848"},{"type":"WEB","url":"http://www.php.net/ChangeLog-5.php#5.5.20"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1175718"}],"affected":[{"package":{"name":"php","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/php?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.20-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0542.json"}},{"package":{"name":"php-apc","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/php-apc?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.15-4.10.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0542.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}