|
|
Log in / Subscribe / Register

Slackware alert SSA:2025-073-02 (php)

From:  Slackware Security Team <security@slackware.com>
To:  slackware-security@slackware.com
Subject:  [slackware-security] php (SSA:2025-073-02)
Date:  Fri, 14 Mar 2025 14:02:31 -0700
Message-ID:  <alpine.LNX.2.02.2503141402070.31637@connie.slackware.com>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] php (SSA:2025-073-02) New php packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ extra/php81/php81-8.1.32-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: LibXML: libxml streams use wrong `content-type` header when requesting a redirected resource. Streams: Stream HTTP wrapper header check might omit basic auth header. Streams: Stream HTTP wrapper truncate redirect location to 1024 bytes. Streams: Streams HTTP wrapper does not fail for headers without colon. Streams: Header parser of http stream wrapper does not handle folded headers. For more information, see: https://www.php.net/ChangeLog-8.php#8.1.32 https://www.cve.org/CVERecord?id=CVE-2025-1219 https://www.cve.org/CVERecord?id=CVE-2025-1736 https://www.cve.org/CVERecord?id=CVE-2025-1861 https://www.cve.org/CVERecord?id=CVE-2025-1734 https://www.cve.org/CVERecord?id=CVE-2025-1217 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated packages for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/extr... Updated packages for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/ex... Updated packages for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/s... ftp://ftp.slackware.com/pub/slackware/slackware-current/t... Updated packages for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current... ftp://ftp.slackware.com/pub/slackware/slackware64-current... MD5 signatures: +-------------+ Slackware 15.0 packages: 7ba31f70c3300ea55ebfa9bd48c8e001 php81-8.1.32-i586-1_slack15.0.txz Slackware x86_64 15.0 packages: 453e0b70f68ee1bc3fd5f55a2b87a46f php81-8.1.32-x86_64-1_slack15.0.txz Slackware -current packages: 8a17a8d98cc13ebf3ff21febfcff9534 n/php-8.3.19-i686-1.txz 762cd3257676a5897acc1e4fcd074acc php-8.4.5-i686-1.txz Slackware x86_64 -current packages: 03d971bf855ca09b2134b61e75ff0999 n/php-8.3.19-x86_64-1.txz 2ff6e389890ead53eb4bfd495b3ecf82 php-8.4.5-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg php81-8.1.32-i586-1_slack15.0.txz Then, restart Apache httpd: # /etc/rc.d/rc.httpd stop # /etc/rc.d/rc.httpd start +-----+ Slackware Linux Security Team http://slackware.com/gpg-key security@slackware.com +------------------------------------------------------------------------+ | To leave the slackware-security mailing list: | +------------------------------------------------------------------------+ | Send an email to majordomo@slackware.com with this text in the body of | | the email message: | | | | unsubscribe slackware-security | | | | You will get a confirmation message back containing instructions to | | complete the process. Please do not reply to this email address. | +------------------------------------------------------------------------+ -----BEGIN PGP SIGNATURE----- iF0EARECAB0WIQTsVknaQB4iq/pnNu9qRGPAQBAiMwUCZ9SYpAAKCRBqRGPAQBAi M+XBAJsFJ67SK3QMTdcMRAw/8w2SE6F31QCeOx62motlM33d76TlChzK5jzCnYA= =z8uS -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds