[Bug 1707960] Review Request: php-brumann-polyfill-unserialize - Backports unserialize options introduced in PHP 7.0

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



https://bugzilla.redhat.com/show_bug.cgi?id=1707960

Shawn Iwinski <shawn@xxxxxxxx> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Blocks|                            |1708652, 1708653, 1708646
                   |                            |(CVE-2019-11830), 1708649
                   |                            |(CVE-2019-11831)




Referenced Bugs:

https://bugzilla.redhat.com/show_bug.cgi?id=1708646
[Bug 1708646] CVE-2019-11830 phar-stream-wrapper: mishandling of phar stub
parsing leads to bypass a deserialization of protection mechanism
https://bugzilla.redhat.com/show_bug.cgi?id=1708649
[Bug 1708649] CVE-2019-11831 phar-stream-wrapper: TYP03 does not prevent
directory traversal resulting in bypass of deserialization of protection
mechanism
https://bugzilla.redhat.com/show_bug.cgi?id=1708652
[Bug 1708652] CVE-2019-11830 CVE-2019-11831 php-typo3-phar-stream-wrapper2:
various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1708653
[Bug 1708653] CVE-2019-11830 CVE-2019-11831 php-typo3-phar-stream-wrapper2:
various flaws [epel-7]
-- 
You are receiving this mail because:
You are on the CC list for the bug.
You are always notified about changes to this product and component
_______________________________________________
package-review mailing list -- package-review@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to package-review-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-review@xxxxxxxxxxxxxxxxxxxxxxx




[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite Conditions]     [KDE Users]

  Powered by Linux