• [SECURITY] [DSA 4992-1] php7.4 security update

    From Salvatore Bonaccorso@21:1/5 to All on Mon Oct 25 22:30:02 2021
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4992-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso October 25, 2021 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : php7.4
    CVE ID : CVE-2021-21703
    Debian Bug : 997003

    An out-of-bounds read and write flaw was discovered in the PHP-FPM code,
    which could result in escalation of privileges from local unprivileged
    user to the root user.

    For the stable distribution (bullseye), this problem has been fixed in
    version 7.4.25-1+deb11u1.

    We recommend that you upgrade your php7.4 packages.

    For the detailed security status of php7.4 please refer to its security
    tracker page at:
    https://security-tracker.debian.org/tracker/php7.4

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmF3EQhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Sirg/9FEi2498AwrLJFd38x/N9F3SndRQXFEyHFoi8vBW7HEurAbPqjLodWCqU ltk+AkOVWS8D1qRYAb8HM8ZUxF6KXZsV6rOQ4W6Gh5qX1I3pIt6LZBWO7ez/Sh8w QTGGPdmrP+Gr8RoTgKHOHxgNc8kgV7gAygdp+ImhylutXHJkwZNnhOmJjRjnzaQy nEH5mPsTTT5YS2W5a0qjQoTK44oGPHZDLq6KtZ6kdwdW9y5L4cToyghYfjw206HD rLlcMoBi7LmQfXm6Ssqi6NmTMNQjyPWKWaBmolRFPhod4T3FMxxWJ21zKpAd3ezp T+LKXlIGXNfgECbZG2xc0045WKPL5RXHKnPrFtfoXQu6PkClrm2PChJHJ9KEGKmx hWCBl5q+V2+jJSbpRsUsKOiTZ7IqphyvF5kqleUrFg85ReNSWUDbG/bzB6WORwdC OF0uCQK5nzwHqhp3i3St61jYUdjCe2bstjcZHjiw5X5o2v5EOC0aLHufiDmtaq2G 7vMHGnrd3RHRMA2aPd62xee0o6jAhycmyRr6u4X9BFgoNWxlD57gK2RuH4MC+Wb5 wUBo74Fy74Z+Bw4ynXR6tHz7rHPvwpRC+7hDATEcEBqE4t72Z4fedxYciLOMwo7Z TZuFZoR3ACOKiOx4z0gnA/X3OG9I49kQrCuTltecdCm3LIs+l+8=
    =kDjO
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)