Red Hat Security Advisory 2020-1112-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Issues addressed include a cross site scripting vulnerability.
0ca548e0ef7f72ae710a0a6b1dd6e143afe4e960d46770e9909508108156f05c
Red Hat Security Advisory 2019-2519-01 - PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Issues addressed include buffer overflow, bypass, cross site scripting, denial of service, information leakage, and null pointer vulnerabilities.
acffbdfe90b0a58970132a1847884fe8bf47723bf6191011cc4ac8b281a95407
Debian Linux Security Advisory 4240-1 - Several vulnerabilities were found in PHP, a widely-used open source general purpose scripting language.
4369be1bc2fc15b16bcbc45b903b8da4f8ffb2ca89575a1dcfff84f66942c227
PHP version 7.2.2 contains a memory corruption bug while parsing malformed HTTP response packets.
667487664aa7c41c76b36c09233708ca134270a43a39a979a5c4fe652c6c0a66
Ubuntu Security Notice 3600-2 - USN-3600-1 fixed a vulnerability in PHP. This update provides the corresponding update for Ubuntu 12.04 ESM. It was discovered that PHP incorrectly handled the PHAR 404 error page. A remote attacker could possibly use this issue to conduct cross-site scripting attacks. Various other issues were also addressed.
7e33e2d4fb4b760a8aab3b3c5cbe3068c322a7deb50876c80a4cf13a345559a6
Ubuntu Security Notice 3600-1 - It was discovered that PHP incorrectly handled certain stream metadata. A remote attacker could possibly use this issue to set arbitrary metadata. This issue only affected Ubuntu 14.04 LTS. It was discovered that PHP incorrectly handled the PHAR 404 error page. A remote attacker could possibly use this issue to conduct cross-site scripting attacks. This issue only affected Ubuntu 16.04 LTS and Ubuntu 17.10. Various other issues were also addressed.
503985a9dba6e5bf22e4b1ea574b04e5d069b65692024a2dd9194c38839ded9d