Debian alert DLA-2465-1 (php-pear)
From: | Chris Lamb <lamby@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 2465-1] php-pear security update | |
Date: | Mon, 23 Nov 2020 06:15:52 -0500 | |
Message-ID: | <160613002135.1757532.5095859641947593223@tinycat.chris-lamb.co.uk> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2465-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb November 23, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : php-pear Version : 1:1.10.1+submodules+notgz-9+deb9u2 CVE IDs : CVE-2020-28948 CVE-2020-28949 It was discovered that there was a filename sanitisation issue in php-pear, a distribution system for reusable PHP components. For Debian 9 "Stretch", this problem has been fixed in version 1:1.10.1+submodules+notgz-9+deb9u2. We recommend that you upgrade your php-pear packages. For the detailed security status of php-pear please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-pear Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl+7mWQACgkQHpU+J9Qx HljlpxAAqFlSEHIZJXniiZzuHAO8HU19qcFJ2XN6eW+OkaAWxFHaQp93xEQJASDp /zrgwrdfPJrrMjoG8IX3bsnEoKruOOjLJZP2YQYCSrc5t+mjk3TkF1luccbmGh2G l3WfHcA5QpTPEuT4EiUI0StVrnT9q8Ogxh2WfLpJ+hlyP5uDcEhUYnie+kVGyanv 7Fy5QulMwRZg673C6NFRPZZW5Qvsa+GuT0DyKVFaKb4BZtZWl5D61ob0ybUG9OSi AZQqDr6yUocyQ0aTSmUpiraCbOvdiAVpotE0SI4EUOCXGY+9BdXFzBG4z1KUS418 nTOhaZxIIIKNApykc42e+iK1yZou4YRp2zzZQMVAajoVD/DKY77ZTV3ToXw+s/IW wediC+6ELWsdGdlAXZWW39ZYU4HHKPCBWOWEy7c/JWOk7i08q6n1UTosDam2ek4R n/R+01bB5Looy6J6Td2slG3YcvXzZ5CaMKmqaMzDF27cFL6Rxx5HAuiZABNFqi84 3ayfPL3kAq08z9SaAXrxcOzgRAPxRoW6/T4fN4kWwoeS31ZQx0pyJdNevgooVrGo o6jzxi8eD+BpbPcnzVhDu7wILcsqtNtUSHCiasKaCFdVwzp9dNn0SmXefN1DBtmK oKqBPqXL5uT6fN8kvPnwsXYyBtM+SaFfss0hUCntQgcA1amIhnI= =AEvq -----END PGP SIGNATURE-----