{"id":"MGASA-2022-0406","summary":"Updated php packages fix security vulnerability","details":"GD - Fixed bug #81739: OOB read due to insufficient input validation in\nimageloadfont().\nHash - Fixed bug #81738: buffer overflow in hash_update() on long\nparameter.\nSession - Fixed bug GH-9583 (session_create_id() fails with user defined\nsave handler that doesn't have a validateId() method).\nStreams - Fixed bug GH-9590 (stream_select does not abort upon exception\nor empty valid fd set)\n","modified":"2026-04-16T04:22:55.065172Z","published":"2022-11-01T22:58:59Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2022-0406.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=31041"},{"type":"WEB","url":"https://www.php.net/ChangeLog-8.php#8.0.25"}],"affected":[{"package":{"name":"php","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/php?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.25-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0406.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}