The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
**Version 2.14.11** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation…
**Version 3.3.8** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation n…
**Version 2.14.11** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation…
Security hotfix release addressing a critical vulnerability in PostgreSQL connections (CVE-2021-3850) Additional fixes: Fix usage of get_magic_* functions #619…
**Version 2.17.1** Bug * 163: Backport GHSA-jq4p-mq33-w375 to v2 thanks to @Slamdunk
**Version 2.17.1** Bug * 163: Backport GHSA-jq4p-mq33-w375 to v2 thanks to @Slamdunk
Out of bounds in php_pcre_replace_impl (CVE-2017-9118) Multiple bugs fixed. See referenced changelog for details. References: - https://bugs.mageia.org/show_bu…
**Version 4.4.35** (2021-11-24) * security **CVE-2021-41270** [Serializer] Use single quote to escape formulas (jderusse) * bug #44232 [Cache] fix connecting t…
**Version 4.4.35** (2021-11-24) * security **CVE-2021-41270** [Serializer] Use single quote to escape formulas (jderusse) * bug #44232 [Cache] fix connecting t…
Header injection via default_mimetype / default_charset mbstring may use pointer from some previous request Unexpected behavior with arrays and JIT Special cha…
ImageMagick is updated 6.9.12.28 , soname bump , many security fixes ---- Add scraper2vdr_serienposter_statt_banner.diff
An update that solves one vulnerability and has one errata is now available.
**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)
**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)
PHPMailer contained a vulnerability that can result in untrusted code being called (CVE-2021-3603). See upstream release notes.
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode (CVE-2021-26119). Smarty before 3.1.39 allows code…
**Version 1.1.4** * Reject paths with funky whitespace.
**Version 1.1.4** * Reject paths with funky whitespace.
**Version 4.4.24** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) * bug #412…
**Version 3.4.49** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) ---- **Ver…
**Version 6.4.1** (April 29th, 2021) * **SECURITY** Fixes CVE-2020-36326, a regression of CVE-2018-19296 object injection introduced in 6.1.8, see SECURITY.md …
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
**Version 4.4.13** (2020-09-02) * security **CVE-2020-15094** Remove headers with internal meaning from HttpClient responses (mpdude) * bug #38024 [Console] Fi…