|
|
Log in / Subscribe / Register

Ubuntu alert USN-8513-1 (php7.0)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8513-1] PHP vulnerabilities
Date:  Mon, 06 Jul 2026 15:11:27 +0000
Message-ID:  <E1wgkyl-0003f3-0L@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8513-1 July 06, 2026 php7.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: PHP could be made to crash or run programs if it received specially crafted network traffic. Software Description: - php7.0: HTML-embedded scripting language interpreter Details: It was discovered that PHP incorrectly handled SOAP object deduplication when processing apache:Map nodes with duplicate keys. An attacker could possibly use this to cause a use-after-free, resulting in remote code execution. (CVE-2026-6722) It was discovered that PHP incorrectly handled SOAP request persistence when configured with SOAP_PERSISTENCE_SESSION. An attacker could possibly use this to cause a use-after-free, resulting in memory corruption, information disclosure, or a denial of service. (CVE-2026-7261) It was discovered that the PDO Firebird driver in PHP improperly handled NUL bytes when quoting SQL query strings. An attacker could possibly use this to perform SQL injection when attacker-controlled values are embedded in SQL statements. (CVE-2025-14179) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS php7.0-interbase 7.0.33-0ubuntu0.16.04.16+esm19 Available with Ubuntu Pro php7.0-soap 7.0.33-0ubuntu0.16.04.16+esm19 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8513-1 CVE-2025-14179, CVE-2026-6722, CVE-2026-7261


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpLxBoACgkQcpJm3tlz hgH3oxAAj6FSgsQ5TuxWF6DE2PuKvzIurJJAl4BGhHH8H8NhjY6TsBTiVJPzbzgq TWngaaZNh57g4yR5KYgJghsy/PI1b3Ca0ADU1/Q7hXOSj8gNC01G+6kto6vFkQAN 102TrJ+nSNM1oFdFLbq4PjCWjoqePD2vV72NKg1QEwSFU68Ows3jMGG3RK6KIrVl 5WobcrxCfEpJdTIWA7RI0JTjlr5DVgW3STvj3AkWCtxInHRUPdouKycm5hZ8F4mW DVlYgaXOOesF7ABIL3UUue7IzxRct7L4+PAJ446HZN21PRIRqE2imlWjte04uZDn dwOHz9jF1QFHK2UflHKlon7dPKJe1iy9cg5fHlOmSe6uIpdE+MWwffG1ykG0Oj/a rz6ITeHgUL0QOCvR3H32mDNuWaypygrTVxiN0MQex1xSMWGwdULlI37dBWJqdfC6 astwjBrQIpqX3CZrFGYMlkGfUtICiCc+ImCEEzr/jSZNE8CMiACOmmapMS1JmesX f1vYIiO4kLmj0Wbc0mmhQ1aOhUKM3ngMLGKMxKiKquXEhSVs7HfvnKvtxs9+yhuU u5husnwqgLFCiKhWxPHQnjRXa19c+mkctMTa6RysrxSr7Ss/PtjqRxQ0/CImu3eV jXUBE6AXi6oMJDekFLFqAE42eagzT2IYUcAiOOiSKNbP/0n56QM= =n0ef -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds