{"id":"MGASA-2020-0387","summary":"Updated php packages fix a security vulnerability","details":"In PHP versions 7.2.x when PHP is processing incoming HTTP cookie values, the\ncookie names are url-decoded. This may lead to cookies with prefixes\nlike __Host confused with cookies that decode to such prefix, thus leading to\nan attacker being able to forge cookie which is supposed to be secure. \n(CVE-2020-7070)\n\nThese updated packages also fix several bugs:\nCore:\n- realpath() erroneously resolves link to link\n- Stack use-after-scope in define()\n- getimagesize function silently truncates after a null byte\n- Memleak when coercing integers to string via variadic argument\n\nFileinfo: finfo_file crash (FILEINFO_MIME)\n\nLDAP: Fixed memory leaks.\n\nOPCache: opcache.file_cache causes SIGSEGV when custom opcode handlers changed.\n\nStandard: Memory leak in str_replace of empty string\n","modified":"2026-04-16T04:44:43.856890551Z","published":"2020-10-16T17:04:43Z","upstream":["CVE-2020-7070"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0387.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27239"},{"type":"WEB","url":"https://www.php.net/ChangeLog-7.php#PHP_7_3_23"},{"type":"WEB","url":"https://www.php.net/ChangeLog-7.php#PHP_7_3_22"},{"type":"WEB","url":"https://www.php.net/ChangeLog-7.php#PHP_7_3_21"}],"affected":[{"package":{"name":"php","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/php?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.3.23-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0387.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}