{"id":"MGASA-2021-0442","summary":"Updated php packages fix security vulnerabilities","details":"Updated php packages fix security vulnerabilities:\n- Integer overflow in mysqli_real_escape_string()\n- Symlinks are followed when creating PHAR archive\n- shmop can't read beyond 2147483647 bytes\n- Integer overflow on substr_replace\n- Heap buffer overflow via str_repeat\n- Integer Overflow when concatenating strings\n- segfault with preloading and statically bound closure\n- shmop_open won't attach and causes php to crash\n- Heap Overflow in msg_send\n- ZipArchive::extractTo extracts outside of destination\n","modified":"2026-04-16T04:24:33.919692Z","published":"2021-09-29T17:22:22Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0442.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29413"},{"type":"WEB","url":"https://www.php.net/ChangeLog-8.php#8.0.10"},{"type":"WEB","url":"https://www.php.net/ChangeLog-8.php#8.0.11"}],"affected":[{"package":{"name":"php","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/php?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.11-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0442.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}