Package Release Info

php7-7.4.6-3.32.1

Update Info: SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-699
Available in Package Hub : 15 SP3 Subpackages Updates

platforms

AArch64
ppc64le
s390x
x86-64

subpackages

php7-embed

Change Logs

* Mon Feb 14 2022 pgajdos@suse.com
- security update
- added patches
  fix CVE-2017-8923 [bsc#1038980], denial of service (application crash) by using .= with a long string (zend_string_extend func in Zend/zend_string.h)
  + php7-CVE-2017-8923.patch
Version: 7.4.6-3.29.1
* Fri Nov 26 2021 pgajdos@suse.com
- security update
- added patches
  fix CVE-2021-21707 [bsc#1193041], special character breaks path in xml parsing
  + php7-CVE-2021-21707.patch
* Fri Oct 29 2021 pgajdos@suse.com
- security update
- added patches
  fix CVE-2021-21703 [bsc#1192050], Local privilege escalation via PHP-FPM
  + php7-CVE-2021-21703.patch
* Mon Oct 04 2021 pgajdos@suse.com
- added patches [bsc#1175508]
  fix https://github.com/php/php-src/pull/7428
  + php7-bsc1175508.patch
Version: 7.4.6-3.22.1
* Mon Aug 02 2021 pgajdos@suse.com
- security update
- added patches
  fix CVE-2021-21704 [bsc#1188035], security issues in pdo_firebase module
  + php7-CVE-2021-21704.patch
* Fri Jul 09 2021 pgajdos@suse.com
- security update
- added patches
  fix CVE-2021-21705 [bsc#1188037], SSRF bypass in FILTER_VALIDATE_URL
  + php7-CVE-2021-21705.patch
Version: 7.4.6-3.17.1
* Thu Feb 11 2021 pgajdos@suse.com
- security update
- added patches
  fix CVE-2021-21702 [bsc#1182049], NULL pointer dereference in SoapClient
  + php7-CVE-2021-21702.patch
Version: 7.4.6-3.14.2
* Mon Jan 11 2021 pgajdos@suse.com
- security update
- added patches
  fix CVE-2020-7071 [bsc#1180706], FILTER_VALIDATE_URL accepts URLs with invalid userinfo
  + php7-CVE-2020-7071.patch
Version: 7.4.6-150200.3.41.1
* Mon Jun 20 2022 pgajdos@suse.com
- security update
- added patches
  fix CVE-2022-31625 [bsc#1200645], uninitialized pointers free in Postgres extension
  + php7-CVE-2022-31625.patch
* Mon Jun 20 2022 pgajdos@suse.com
- security update
- added patches
  fix CVE-2022-31626 [bsc#1200628], buffer overflow via user-supplied password when using pdo_mysql extension with mysqlnd driver
  + php7-CVE-2022-31626.patch
Version: 7.4.6-150200.3.38.2
* Fri May 06 2022 pgajdos@suse.com
- security update [bsc#1197644]
- added patches
  fix https://github.com/php/php-src/commit/771dbdb319fa7f90584f6b2cc2c54ccff570492d
  + php7-signedness-php_filter_validate_domain.patch
Version: 7.4.33-150200.3.46.2
* Thu Nov 03 2022 pgajdos@suse.com
- version update to 7.4.33 [bsc#1204577][bsc#1204979]
    03 Nov 2022
    GD:
    Fixed bug #81739: OOB read due to insufficient input validation in imageloadfont(). (CVE-2022-31630)
    Hash:
    Fixed bug #81738: buffer overflow in hash_update() on long parameter. (CVE-2022-37454)
* Mon Oct 03 2022 pgajdos@suse.com
- version update to 7.4.32 [jsc#SLE-23639]
  Version 7.4.32
  29 Sep 2022
    Core:
    Fixed bug #81726: phar wrapper: DOS when using quine gzip file. (CVE-2022-31628)
    Fixed bug #81727: Don't mangle HTTP variable names that clash with ones that have a specific semantic meaning. (CVE-2022-31629)
  Version 7.4.30
  09 Jun 2022
    mysqlnd:
    Fixed bug #81719: mysqlnd/pdo password buffer overflow. (CVE-2022-31626)
    pgsql:
    Fixed bug #81720: Uninitialized array in pg_query_params(). (CVE-2022-31625)
  Version 7.4.29
  14 Apr 2022
    Core:
    No source changes to this release. This update allows for re-building the Windows binaries against upgraded dependencies which have received security updates.
    Date:
    Updated to latest IANA timezone database (2022a).
  Version 7.4.28
  17 Feb 2022
    Filter:
    Fix #81708: UAF due to php_filter_float() failing for ints (CVE-2021-21708)
  Version 7.4.27
  16 Dec 2021
    Core:
    Fixed bug #81626 (Error on use static:: in __?allStatic() wrapped to Closure::fromCallable()).
    FPM:
    Fixed bug #81513 (Future possibility for heap overflow in FPM zlog).
    GD:
    Fixed bug #71316 (libpng warning from imagecreatefromstring).
    OpenSSL:
    Fixed bug #75725 (./configure: detecting RAND_egd).
    PCRE:
    Fixed bug #74604 (Out of bounds in php_pcre_replace_impl).
    Standard:
    Fixed bug #81618 (dns_get_record fails on FreeBSD for missing type).
    Fixed bug #81659 (stream_get_contents() may unnecessarily overallocate).
  Version 7.4.26
  18 Nov 2021
    Core:
    Fixed bug #81518 (Header injection via default_mimetype / default_charset).
    Date:
    Fixed bug #81500 (Interval serialization regression since 7.3.14 / 7.4.2).
    MBString:
    Fixed bug #76167 (mbstring may use pointer from some previous request).
    MySQLi:
    Fixed bug #81494 (Stopped unbuffered query does not throw error).
    PCRE:
    Fixed bug #81424 (PCRE2 10.35 JIT performance regression).
    Streams:
    Fixed bug #54340 (Memory corruption with user_filter).
    XML:
    Fixed bug #79971 (special character is breaking the path in xml function). (CVE-2021-21707)
  Version 7.4.25
  21 Oct 2021
    DOM:
    Fixed bug #81433 (DOMElement::setIdAttribute() called twice may remove ID).
    FFI:
    Fixed bug #79576 ("TYPE *" shows unhelpful message when type is not defined).
    Fileinfo:
    Fixed bug #78987 (High memory usage during encoding detection).
    Filter:
    Fixed bug #61700 (FILTER_FLAG_IPV6/FILTER_FLAG_NO_PRIV|RES_RANGE failing).
    FPM:
    Fixed bug #81026 (PHP-FPM oob R/W in root process leading to privilege escalation) (CVE-2021-21703).
    SPL:
    Fixed bug #80663 (Recursive SplFixedArray::setSize() may cause double-free).
    Streams:
    Fixed bug #81475 (stream_isatty emits warning with attached stream wrapper).
    XML:
    Fixed bug #70962 (XML_OPTION_SKIP_WHITE strips embedded whitespace).
    Zip:
    Fixed bug #81490 (ZipArchive::extractTo() may leak memory).
    Fixed bug #77978 (Dirname ending in colon unzips to wrong dir).
  Version 7.4.24
  23 Sep 2021
    Core:
    Fixed bug #81302 (Stream position after stream filter removed).
    Fixed bug #81346 (Non-seekable streams don't update position after write).
    Fixed bug #73122 (Integer Overflow when concatenating strings). (CVE-2017-8923)
    GD:
    Fixed bug #53580 (During resize gdImageCopyResampled cause colors change).
    Opcache:
    Fixed bug #81353 (segfault with preloading and statically bound closure).
    Shmop:
    Fixed bug #81407 (shmop_open won't attach and causes php to crash).
    Standard:
    Fixed bug #71542 (disk_total_space does not work with relative paths).
    Fixed bug #81400 (Unterminated string in dns_get_record() results).
    SysVMsg:
    Fixed bug #78819 (Heap Overflow in msg_send).
    XML:
    Fixed bug #81351 (xml_parse may fail, but has no error code).
    Zip:
    Fixed bug #81420 (ZipArchive::extractTo extracts outside of destination). (CVE-2021-21706)
  Version 7.4.23
  26 Aug 2021
    Core:
    Fixed bug #72595 (php_output_handler_append illegal write access).
    Fixed bug #66719 (Weird behaviour when using get_called_class() with call_user_func()).
    Fixed bug #81305 (Built-in Webserver Drops Requests With "Upgrade" Header).
    BCMath:
    Fixed bug #78238 (BCMath returns "-0").
    CGI:
    Fixed bug #80849 (HTTP Status header truncation).
    GD:
    Fixed bug #51498 (imagefilledellipse does not work for large circles).
    MySQLi:
    Fixed bug #74544 (Integer overflow in mysqli_real_escape_string()).
    OpenSSL:
    Fixed bug #81327 (Error build openssl extension on php 7.4.22).
    PDO_ODBC:
    Fixed bug #81252 (PDO_ODBC doesn't account for SQL_NO_TOTAL).
    Phar:
    Fixed bug #81211: Symlinks are followed when creating PHAR archive.(cmb)
    Shmop:
    Fixed bug #81283 (shmop can't read beyond 2147483647 bytes).
    Standard:
    Fixed bug #72146 (Integer overflow on substr_replace).
    Fixed bug #81265 (getimagesize returns 0 for 256px ICO images).
    Fixed bug #74960 (Heap buffer overflow via str_repeat).
    Streams:
    Fixed bug #81294 (Segfault when removing a filter).
  Version 7.4.22
  29 Jul 2021
    Core:
    Fixed bug #81145 (copy() and stream_copy_to_stream() fail for +4GB files).
    Fixed bug #81163 (incorrect handling of indirect vars in __sleep).
    Fixed bug #80728 (PHP built-in web server resets timeout when it can kill the process).
    Fixed bug #73630 (Built-in Webserver - overwrite $_SERVER['request_uri']).
    Fixed bug #80173 (Using return value of zend_assign_to_variable() is not safe).
    Fixed bug #73226 (--r[fcez] always return zero exit code).
    Intl:
    Fixed bug #72809 (Locale::lookup() wrong result with canonicalize option).
    Fixed bug #68471 (IntlDateFormatter fails for "GMT+00:00" timezone).
    Fixed bug #74264 (grapheme_strrpos() broken for negative offsets).
    OpenSSL:
    Fixed bug #52093 (openssl_csr_sign truncates $serial).
    PCRE:
    Fixed bug #81101 (PCRE2 10.37 shows unexpected result).
    Fixed bug #81243 (Too much memory is allocated for preg_replace()).
    Standard:
    Fixed bug #81223 (flock() only locks first byte of file).
  Version 7.4.21
  01 Jul 2021
    Core:
    Fixed bug #81068 (Double free in realpath_cache_clean()).
    Fixed bug #76359 (open_basedir bypass through adding "..").
    Fixed bug #81090 (Typed property performance degradation with .= operator).
    Fixed bug #81070 (Integer underflow in memory limit comparison).
    Fixed bug #81122 (SSRF bypass in FILTER_VALIDATE_URL). (CVE-2021-21705)
    Bzip2:
    Fixed bug #81092 (fflush before stream_filter_remove corrupts stream).
    OpenSSL:
    Fixed bug #76694 (native Windows cert verification uses CN as server name).
    PDO_Firebird:
    Fixed bug #76448 (Stack buffer overflow in firebird_info_cb). (CVE-2021-21704)
    Fixed bug #76449 (SIGSEGV in firebird_handle_doer). (CVE-2021-21704)
    Fixed bug #76450 (SIGSEGV in firebird_stmt_execute). (CVE-2021-21704)
    Fixed bug #76452 (Crash while parsing blob data in firebird_fetch_blob). (CVE-2021-21704)
    Standard:
    Fixed bug #81048 (phpinfo(INFO_VARIABLES) "Array to string conversion").
  Version 7.4.20
  03 Jun 2021
    Core:
    Fixed bug #80929 (Method name corruption related to repeated calls to call_user_func_array).
    Fixed bug #80960 (opendir() warning wrong info when failed on Windows).
    Fixed bug #67792 (HTTP Authorization schemes are treated as case-sensitive).
    Fixed bug #80972 (Memory exhaustion on invalid string offset).
    FPM:
    Fixed bug #65800 (Events port mechanism).
    FTP:
    Fixed bug #80901 (Info leak in ftp extension).
    Fixed bug #79100 (Wrong FTP error messages).
    GD:
    Fixed bug #81032 (GD install is affected by external libgd installation).
    MBString:
    Fixed bug #81011 (mb_convert_encoding removes references from arrays).
    ODBC:
    Fixed bug #80460 (ODBC doesn't account for SQL_NO_TOTAL indicator).
    PDO_MySQL:
    Fixed bug #81037 (PDO discards error message text from prepared statement).
    PDO_ODBC:
    Fixed bug #44643 (bound parameters ignore explicit type definitions).
    pgsql:
    Fixed php_pgsql_fd_cast() wrt. php_stream_can_cast().
    SPL:
    Fixed bug #80933 (SplFileObject::DROP_NEW_LINE is broken for NUL and CR).
    Opcache:
    Fixed bug #80900 (switch statement behavior inside function).
    Fixed bug #81015 (Opcache optimization assumes wrong part of ternary operator in if-condition).
    XMLReader:
    Fixed bug #73246 (XMLReader: encoding length not checked).
    Zip:
    Fixed bug #80863 (ZipArchive::extractTo() ignores references).
  Version 7.4.19
  06 May 2021
    PDO_pgsql:
    Reverted bug fix for #80892 (PDO::PARAM_INT is treated the same as PDO::PARAM_STR).
  Version 7.4.18
  29 Apr 2021
    Core:
    Fixed bug #80781 (Error handler that throws ErrorException infinite loop).
    Fixed bug #75776 (Flushing streams with compression filter is broken).
    Dba:
    Fixed bug #80817 (dba_popen() may cause segfault during RSHUTDOWN).
    DOM:
    Fixed bug #66783 (UAF when appending DOMDocument to element).
    FPM:
    Fixed bug #80024 (Duplication of info about inherited socket after pool removing).
    FTP:
    Fixed bug #80880 (SSL_read on shutdown, ftp/proc_open).
    Imap:
    Fixed bug #80710 (imap_mail_compose() header injection).
    Intl:
    Fixed bug #80763 (msgfmt_format() does not accept DateTime references).
    LibXML:
    Fixed bug #51903 (simplexml_load_file() doesn't use HTTP headers).
    Fixed bug #73533 (Invalid memory access in php_libxml_xmlCheckUTF8).
    MySQLnd:
    Fixed bug #80713 (SegFault when disabling ATTR_EMULATE_PREPARES and MySQL 8.0).
    Fixed bug #80837 (Calling stmt_store_result after fetch doesn't throw an error).
    Fixed bug #78680 (mysqlnd's mysql_clear_password does not transmit null-terminated password).
    Opcache:
    Fixed bug #80805 (create simple class and get error in opcache.so).
    Fixed bug #80950 (Variables become null in if statements).
    Pcntl:
    Fixed bug #79812 (Potential integer overflow in pcntl_exec()).
    PCRE:
    Fixed bug #80866 (preg_split ignores limit flag when pattern with \K has 0-width fullstring match).
    PDO_ODBC:
    Fixed bug #80783 (PDO ODBC truncates BLOB records at every 256th byte).
    PDO_pgsql:
    Fixed bug #80892 (PDO::PARAM_INT is treated the same as PDO::PARAM_STR).
    phpdbg:
    Fixed bug #80757 (Exit code is 0 when could not open file).
    Session:
    Fixed bug #80774 (session_name() problem with backslash).
    Fixed bug #80889 (Cannot set save handler when save_handler is invalid).
    SOAP:
    Fixed bug #69668 (SOAP special XML characters in namespace URIs not encoded).
    Standard:
    Fixed bug #78719 (http wrapper silently ignores long Location headers).
    Fixed bug #80771 (phpinfo(INFO_CREDITS) displays nothing in CLI).
    Fixed bug #80838 (HTTP wrapper waits for HTTP 1 response after HTTP 101).
    Fixed bug #80915 (Taking a reference to $_SERVER hides its values from phpinfo()).
    Fixed bug #80654 (file_get_contents() maxlen fails above (2**31)-1 bytes).
    MySQLi:
    Fixed bug #74779 (x() and y() truncating floats to integers).
    OPcache:
    Fixed bug #80682 (opcache doesn't honour pcre.jit option).
    OpenSSL:
    Fixed bug #80747 (Providing RSA key size < 512 generates key that crash PHP).
    Phar:
    Fixed bug #75850 (Unclear error message wrt. __halt_compiler() w/o semicolon) (cmb)
    Fixed bug #70091 (Phar does not mark UTF-8 filenames in ZIP archives).
    Fixed bug #53467 (Phar cannot compress large archives).
    SPL:
    Fixed bug #80719 (Iterating after failed ArrayObject::setIteratorClass() causes Segmentation fault).
    Zip:
    Fixed bug #80648 (Fix for bug 79296 should be based on runtime version).
  Version 7.4.16
  04 Mar 2021
    Core:
    Fixed bug #80706 (mail(): Headers after Bcc headers may be ignored).
    MySQLnd:
    Fixed bug #78680 (mysqlnd's mysql_clear_password does not transmit null-terminated password).
    MySQLi:
    Fixed bug #74779 (x() and y() truncating floats to integers).
    OPcache:
    Fixed bug #80682 (opcache doesn't honour pcre.jit option).
    OpenSSL:
    Fixed bug #80747 (Providing RSA key size < 512 generates key that crash PHP).
    Phar:
    Fixed bug #75850 (Unclear error message wrt. __halt_compiler() w/o semicolon) (cmb)
    Fixed bug #70091 (Phar does not mark UTF-8 filenames in ZIP archives).
    Fixed bug #53467 (Phar cannot compress large archives).
    SPL:
    Fixed bug #80719 (Iterating after failed ArrayObject::setIteratorClass() causes Segmentation fault).
    Standard:
    Fixed bug #80654 (file_get_contents() maxlen fails above (2**31)-1 bytes).
    Zip:
    Fixed bug #80648 (Fix for bug 79296 should be based on runtime version).
  Version 7.4.15
  04 Feb 2021
    Core:
    Fixed bug #80523 (bogus parse error on >4GB source code).
    Fixed bug #80384 (filter buffers entire read until file closed).
    Curl:
    Fixed bug #80595 (Resetting POSTFIELDS to empty array breaks request).
    Date:
    Fixed bug #80376 (last day of the month causes runway cpu usage.
    MySQLi:
    Fixed bug #67983 (mysqlnd with MYSQLI_OPT_INT_AND_FLOAT_NATIVE fails to interpret bit columns).
    Fixed bug #64638 (Fetching resultsets from stored procedure with cursor fails).
    Fixed bug #72862 (segfault using prepared statements on stored procedures that use a cursor).
    Fixed bug #77935 (Crash in mysqlnd_fetch_stmt_row_cursor when calling an SP with a cursor).
    Phar:
    Fixed bug #77565 (Incorrect locator detection in ZIP-based phars).
    Fixed bug #69279 (Compressed ZIP Phar extractTo() creates garbage files).
    SOAP:
    Fixed bug #80672 (Null Dereference in SoapClient). (CVE-2021-21702)
  Version 7.4.14
  07 Jan 2021
    Core:
    Fixed bug #74558 (Can't rebind closure returned by Closure::fromCallable()).
    Fixed bug #80345 (PHPIZE configuration has outdated PHP_RELEASE_VERSION).
    Fixed bug #72964 (White space not unfolded for CC/Bcc headers).
    Fixed bug #80362 (Running dtrace scripts can cause php to crash).
    Fixed bug #80393 (Build of PHP extension fails due to configuration gap with libtool).
    Fixed bug #80402 (configure filtering out -lpthread).
    Fixed bug #77069 (stream filter loses final block of data).
    Fileinfo:
    Fixed bug #77961 (finfo_open crafted magic parsing SIGABRT).
    FPM:
    Fixed bug #69625 (FPM returns 200 status on request without SCRIPT_FILENAME env).
    Intl:
    Fixed bug #80425 (MessageFormatAdapter::getArgTypeList redefined).
    OpenSSL:
    Fixed bug #80368 (OpenSSL extension fails to build against LibreSSL due to lack of OCB support).
    Phar:
    Fixed bug #73809 (Phar Zip parse crash - mmap fail).
    Fixed bug #75102 (`PharData` says invalid checksum for valid tar).
    Fixed bug #77322 (PharData::addEmptyDir('/') Possible integer overflow).
    PDO MySQL:
    Fixed bug #80458 (PDOStatement::fetchAll() throws for upsert queries).
    Fixed bug #63185 (nextRowset() ignores MySQL errors with native prepared statements).
    Fixed bug #78152 (PDO::exec() - Bad error handling with multiple commands).
    Fixed bug #70066 (Unexpected "Cannot execute queries while other unbuffered queries").
    Fixed bug #71145 (Multiple statements in init command triggers unbuffered query error).
    Fixed bug #76815 (PDOStatement cannot be GCed/closeCursor-ed when a PROCEDURE resultset SIGNAL).
    Standard:
    Fixed bug #77423 (FILTER_VALIDATE_URL accepts URLs with invalid userinfo). (CVE-2020-7071)
    Fixed bug #80366 (Return Value of zend_fstat() not Checked).
    Fixed bug #80411 (References to null-serialized object break serialize()).
    Tidy:
    Fixed bug #77594 (ob_tidyhandler is never reset).
    Zlib:
    Fixed bug #48725 (Support for flushing in zlib stream).
  Version 7.4.13
  26 Nov 2020
    Core:
    Fixed bug #80280 (ADD_EXTENSION_DEP() fails for ext/standard and ext/date).
    Fixed bug #80258 (Windows Deduplication Enabled, randon permission errors).
    COM:
    Fixed bug #62474 (com_event_sink crashes on certain arguments).
    DOM:
    Fixed bug #80268 (loadHTML() truncates at NUL bytes).
    FFI:
    Fixed bug #79177 (FFI doesn't handle well PHP exceptions within callback).
    IMAP:
    Fixed bug #64076 (imap_sort() does not return FALSE on failure).
    Fixed bug #76618 (segfault on imap_reopen).
    Fixed bug #80239 (imap_rfc822_write_address() leaks memory).
    Fixed minor regression caused by fixing bug #80220.
    Fixed bug #80242 (imap_mail_compose() segfaults for multipart with rfc822).
    MySQLi:
    Fixed bug #79375 (mysqli_store_result does not report error from lock wait timeout).
    Fixed bug #76525 (mysqli::commit does not throw if MYSQLI_REPORT_ERROR enabled and mysqlnd used).
    Fixed bug #72413 (mysqlnd segfault (fetch_row second parameter typemismatch)).
    ODBC:
    Fixed bug #44618 (Fetching may rely on uninitialized data).
    Opcache:
    Fixed bug #79643 (PHP with Opcache crashes when a file with specific name is included).
    Fixed run-time binding of preloaded dynamically declared function.
    OpenSSL:
    Fixed bug #79983 (openssl_encrypt / openssl_decrypt fail with OCB mode).
    PDO MySQL:
    Fixed bug #66528 (No PDOException or errorCode if database becomes unavailable before PDO::commit).
    Fixed bug #65825 (PDOStatement::fetch() does not throw exception on broken server connection).
    SNMP:
    Fixed bug #70461 (disable md5 code when it is not supported in net-snmp).
    Standard:
    Fixed bug #80266 (parse_url silently drops port number 0).
  Version 7.4.12
  29 Oct 2020
    Core:
    Fixed bug #80061 (Copying large files may have suboptimal performance).
    Fixed bug #79423 (copy command is limited to size of file it can copy).
    Fixed bug #80126 (Covariant return types failing compilation).
    Fixed bug #80186 (Segfault when iterating over FFI object).
    Calendar:
    Fixed bug #80185 (jdtounix() fails after 2037).
    IMAP:
    Fixed bug #80213 (imap_mail_compose() segfaults on certain $bodies).
    Fixed bug #80215 (imap_mail_compose() may modify by-val parameters).
    Fixed bug #80220 (imap_mail_compose() may leak memory).
    Fixed bug #80223 (imap_mail_compose() leaks envelope on malformed bodies).
    Fixed bug #80216 (imap_mail_compose() does not validate types/encodings).
    Fixed bug #80226 (imap_sort() leaks sortpgm memory).
    MySQLnd:
    Fixed bug #80115 (mysqlnd.debug doesn't recognize absolute paths with slashes).
    Fixed bug #80107 (mysqli_query() fails for ~16 MB long query when compression is enabled).
    ODBC:
    Fixed bug #78470 (odbc_specialcolumns() no longer accepts $nullable).
    Fixed bug #80147 (BINARY strings may not be properly zero-terminated).
    Fixed bug #80150 (Failure to fetch error message).
    Fixed bug #80152 (odbc_execute() moves internal pointer of $params).
    Fixed bug #46050 (odbc_next_result corrupts prepared resource).
    OPcache:
    Fixed bug #80083 (Optimizer pass 6 removes variables used for ibm_db2 data binding).
    Fixed bug #80194 (Assertion failure during block assembly of unreachable free with leading nop).
    PCRE:
    Updated to PCRE 10.35.
    Fixed bug #80118 (Erroneous whitespace match with JIT only).
    PDO_ODBC:
    Fixed bug #67465 (NULL Pointer dereference in odbc_handle_preparer).
    Standard:
    Fixed bug #80114 (parse_url does not accept URLs with port 0).
    Fixed bug #76943 (Inconsistent stream_wrapper_restore() errors).
    Fixed bug #76735 (Incorrect message in fopen on invalid mode).
    Tidy:
    Fixed bug #77040 (tidyNode::isHtml() is completely broken).
  Version 7.4.11
  01 Oct 2020
    Core:
    Fixed bug #79699 (PHP parses encoded cookie names so malicious `__Host-` cookies can be sent). (CVE-2020-7070)
    Fixed bug #79979 (passing value to by-ref param via CUFA crashes).
    Fixed bug #80037 (Typed property must not be accessed before initialization when __get() declared).
    Fixed bug #80048 (Bug #69100 has not been fixed for Windows).
    Fixed bug #80049 (Memleak when coercing integers to string via variadic argument).
    Calendar:
    Fixed bug #80007 (Potential type confusion in unixtojd() parameter parsing).
    COM:
    Fixed bug #64130 (COM obj parameters passed by reference are not updated).
    OPcache:
    Fixed bug #80002 (calc free space for new interned string is wrong).
    Fixed bug #80046 (FREE for SWITCH_STRING optimized away).
    Fixed bug #79825 (opcache.file_cache causes SIGSEGV when custom opcode handlers changed).
    OpenSSL:
    Fixed bug #79601 (Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV). (CVE-2020-7069)
    PDO:
    Fixed bug #80027 (Terrible performance using $query->fetch on queries with many bind parameters).
    SOAP:
    Fixed bug #47021 (SoapClient stumbles over WSDL delivered with "Transfer-Encoding: chunked").
    Standard:
    Fixed bug #79986 (str_ireplace bug with diacritics characters).
    Fixed bug #80077 (getmxrr test bug).
    Fixed bug #72941 (Modifying bucket->data by-ref has no effect any longer).
    Fixed bug #80067 (Omitting the port in bindto setting errors).
  Version 7.4.10
  03 Sep 2020
    Core:
    Fixed bug #79884 (PHP_CONFIG_FILE_PATH is meaningless).
    Fixed bug #77932 (File extensions are case-sensitive).
    Fixed bug #79806 (realpath() erroneously resolves link to link).
    Fixed bug #79895 (PHP_CHECK_GCC_ARG does not allow flags with equal sign).
    Fixed bug #79919 (Stack use-after-scope in define()).
    Fixed bug #79934 (CRLF-only line in heredoc causes parsing error).
    Fixed bug #79947 (Memory leak on invalid offset type in compound assignment).
    COM:
    Fixed bug #48585 (com_load_typelib holds reference, fails on second call).
    Exif:
    Fixed bug #75785 (Many errors from exif_read_data).
    Gettext:
    Fixed bug #70574 (Tests fail due to relying on Linux fallback behavior for gettext()).
    LDAP:
    Fixed memory leaks.
    OPcache:
    Fixed bug #73060 (php failed with error after temp folder cleaned up).
    Fixed bug #79917 (File cache segfault with a static variable in inherited method).
    PDO:
    Fixed bug #64705 (errorInfo property of PDOException is null when PDO::__construct() fails).
    Session:
    Fixed bug #79724 (Return type does not match in ext/session/mod_mm.c).
    Standard:
    Fixed bug #79930 (array_merge_recursive() crashes when called with array with single reference).
    Fixed bug #79944 (getmxrr always returns true on Alpine linux).
    Fixed bug #79951 (Memory leak in str_replace of empty string).
    XML:
    Fixed bug #79922 (Crash after multiple calls to xml_parser_free()).
  Version 7.4.9
  06 Aug 2020
    Apache:
    Fixed bug #79030 (Upgrade apache2handler's php_apache_sapi_get_request_time to return usec).
    COM:
    Fixed bug #63208 (BSTR to PHP string conversion not binary safe).
    Fixed bug #63527 (DCOM does not work with Username, Password parameter).
    Core:
    Fixed bug #79740 (serialize() and unserialize() methods can not be called statically).
    Fixed bug #79783 (Segfault in php_str_replace_common).
    Fixed bug #79778 (Assertion failure if dumping closure with unresolved static variable).
    Fixed bug #79779 (Assertion failure when assigning property of string offset by reference).
    Fixed bug #79792 (HT iterators not removed if empty array is destroyed).
    Fixed bug #78598 (Changing array during undef index RW error segfaults).
    Fixed bug #79784 (Use after free if changing array during undef var during array write fetch).
    Fixed bug #79793 (Use after free if string used in undefined index warning is changed).
    Fixed bug #79862 (Public non-static property in child should take priority over private static).
    Fixed bug #79877 (getimagesize function silently truncates after a null byte) (cmb)
    Fileinfo:
    Fixed bug #79756 (finfo_file crash (FILEINFO_MIME)).
    FTP:
    Fixed bug #55857 (ftp_size on large files).
    Mbstring:
    Fixed bug #79787 (mb_strimwidth does not trim string).
    Phar:
    Fixed bug #79797 (Use of freed hash key in the phar_parse_zipfile function). (CVE-2020-7068)
    Reflection:
    Fixed bug #79487 (::getStaticProperties() ignores property modifications).
    Fixed bug #69804 (::getStaticPropertyValue() throws on protected props).
    Fixed bug #79820 (Use after free when type duplicated into ReflectionProperty gets resolved).
    Standard:
    Fixed bug #70362 (Can't copy() large 'data://' with open_basedir).
    Fixed bug #78008 (dns_check_record() always return true on Alpine).
    Fixed bug #79839 (array_walk() does not respect property types).
  Version 7.4.8
  09 Jul 2020
    Core:
    Fixed bug #79595 (zend_init_fpu() alters FPU precision).
    Fixed bug #79650 (php-win.exe 100% cpu lockup).
    Fixed bug #79668 (get_defined_functions(true) may miss functions).
    Fixed bug #79683 (Fake reflection scope affects __toString()).
    Fixed possibly unsupported timercmp() usage.
    Exif:
    Fixed bug #79687 (Sony picture - PHP Warning - Make, Model, MakerNotes).
    Fileinfo:
    Fixed bug #79681 (mime_content_type/finfo returning incorrect mimetype).
    Filter:
    Fixed bug #73527 (Invalid memory access in php_filter_strip).
    GD:
    Fixed bug #79676 (imagescale adds black border with IMG_BICUBIC).
    OpenSSL:
    Fixed bug #62890 (default_socket_timeout=-1 causes connection to timeout).
    PDO SQLite:
    Fixed bug #79664 (PDOStatement::getColumnMeta fails on empty result set).
    phpdbg:
    Fixed bug #73926 (phpdbg will not accept input on restart execution).
    Fixed bug #73927 (phpdbg fails with windows error prompt at "watch array").
    Fixed several mostly Windows related phpdbg bugs.
    SPL:
    Fixed bug #79710 (Reproducible segfault in error_handler during GC involved an SplFileObject).
    Standard:
    Fixed bug #74267 (segfault with streams and invalid data).
  Version 7.4.7
  11 Jun 2020
    Core:
    Fixed bug #79599 (coredump in set_error_handler).
    Fixed bug #79566 (Private SHM is not private on Windows).
    Fixed bug #79489 (.user.ini does not inherit).
    Fixed bug #79600 (Regression in 7.4.6 when yielding an array based generator).
    Fixed bug #79657 ("yield from" hangs when invalid value encountered).
    FFI:
    Fixed bug #79571 (FFI: var_dumping unions may segfault).
    GD:
    Fixed bug #79615 (Wrong GIF header written in GD GIFEncode).
    MySQLnd:
    Fixed bug #79596 (MySQL FLOAT truncates to int some locales).
    Opcache:
    Fixed bug #79588 (Boolean opcache settings ignore on/off values).
    Fixed bug #79548 (Preloading segfault with inherited method using static variable).
    Fixed bug #79603 (RTD collision with opcache).
    Standard:
    Fixed bug #79561 (dns_get_record() fails with DNS_ALL).
- fixes [bsc#1203867] and [bsc#1203870]
- modified patches
  % php-no-build-date.patch (refreshed)
  % php7-arm-build-fixes.patch (refreshed)
- deleted patches
  - php-fix_net-snmp_disable_MD5.patch (upstreamed)
  - php-odbc-cmp-int-cast.patch (not needed,
    dropped from factory as well, see
    last comment of
    https://bugs.php.net/bug.php?id=52554)
  - php7-CVE-2017-8923.patch (upstreamed)
  - php7-CVE-2020-7068.patch (upstreamed)
  - php7-CVE-2020-7069.patch (upstreamed)
  - php7-CVE-2020-7070.patch (upstreamed)
  - php7-CVE-2020-7071.patch (upstreamed)
  - php7-CVE-2021-21702.patch (upstreamed)
  - php7-CVE-2021-21703.patch (upstreamed)
  - php7-CVE-2021-21704.patch (upstreamed)
  - php7-CVE-2021-21705.patch (upstreamed)
  - php7-CVE-2021-21707.patch (upstreamed)
  - php7-CVE-2021-21708.patch (upstreamed)
  - php7-CVE-2022-31625.patch (upstreamed)
  - php7-CVE-2022-31626.patch (upstreamed)
Version: 7.2.5-4.67.2
* Mon Oct 12 2020 pgajdos@suse.com
- fix ghost name for /run/php-fpm [bsc#1173786]
* Fri Oct 09 2020 pgajdos@suse.com
- security update
- added patches
  fix CVE-2020-7069 [bsc#1177351], when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is used
  + php7-CVE-2020-7069.patch
  fix CVE-2020-7070 [bsc#1177352], Percent-encoded cookies can be used to overwrite existing prefixed cookie names
  + php7-CVE-2020-7070.patch
Version: 7.2.5-4.61.1
* Thu Aug 13 2020 pgajdos@suse.com
- security update
- added patches
  fix CVE-2020-7068 [bsc#1175223], Use of freed hash key in the phar_parse_zipfile function
  + php7-CVE-2020-7068.patch
* Tue Aug 04 2020 pgajdos@suse.com
- do not install outdated README.SUSE [bsc#1174010]
* Thu Jul 09 2020 pgajdos@suse.com
- do not install %{_tmpfilesdir}, %{_tmpfilesdir}/php-fpm.conf in
  test favour
* Mon Jul 06 2020 daniel.molkentin@suse.com
- added tmpfiles.d for php-fpm to provide a base base for a socket
  (boo#1173786)
Version: 7.2.5-4.58.2
* Mon May 25 2020 pgajdos@suse.com
- security update
- added patches
  fix CVE-2019-11048 [bsc#1171999], supplying overly long filenames or field names if HTTP file uploads are allowed could lead to exhausting disk space on the server
  + php7-CVE-2019-11048.patch
* Tue Apr 07 2020 pgajdos@suse.com
- security update
- added patches
  fix CVE-2020-7064 [bsc#1168326], read one byte of uninitialized memory via malicious data
  + php7-CVE-2020-7064.patch
  fix CVE-2020-7066 [bsc#1168352], URL truncation if the URL contains zero (\0) character
  + php7-CVE-2020-7066.patch
* Mon Mar 02 2020 pgajdos@suse.com
- security update
- added patches
  fix CVE-2020-7062 [bsc#1165280], null pointer dereference when using file upload functionality under specific circumstances
  + php7-CVE-2020-7062.patch
  fix CVE-2020-7063 [bsc#1165289], creating PHAR archive using PharData:buildFromIterator() function will add files with default permissions
  + php7-CVE-2020-7063.patch
* Wed Feb 05 2020 pgajdos@suse.com
- security update
- added patches
  CVE-2020-7059 [bsc#1162629]
  + php7-CVE-2020-7059.patch
  CVE-2020-7060 [bsc#1162632]
  + php7-CVE-2020-7060.patch
Version: 7.2.5-4.49.1
* Thu Jan 02 2020 pgajdos@suse.com
- security update
- added patches
  CVE-2019-11045 [bsc#1159923]
  + php7-CVE-2019-11045.patch
  CVE-2019-11046 [bsc#1159924]
  + php7-CVE-2019-11046.patch
  CVE-2019-11047 [bsc#1159922]
  + php7-CVE-2019-11047.patch
  CVE-2019-11050 [bsc#1159927]
  + php7-CVE-2019-11050.patch
Version: 7.2.5-4.46.1
* Fri Oct 25 2019 pgajdos@suse.com
- security update
- added patches
  CVE-2019-11043 [bsc#1154999]
  + php7-CVE-2019-11043.patch
Version: 7.2.5-4.43.2
* Fri Oct 04 2019 pgajdos@suse.com
- provide test results via multibuild :test [bsc#1119396]
- added sources
  + _multibuild
Version: 7.2.5-4.40.1
* Thu Sep 26 2019 pgajdos@suse.com
- drop -n from php invocation from pecl [bsc#1151793]
  https://github.com/pear/pear-core/commit/f94454a74785865cec50bf9d64c410efc29b587a
* Thu Sep 26 2019 pgajdos@suse.com
- turn off run of testsuite as we get Kernel panic on s390x
* Thu Aug 22 2019 pgajdos@suse.com
- security update
- added patches
  CVE-2019-11041 [bsc#1146360]
  + php7-CVE-2019-11041.patch
  CVE-2019-11042 [bsc#1145095]
  + php7-CVE-2019-11042.patch
Version: 7.2.5-4.35.3
* Fri Jun 14 2019 pgajdos@suse.com
- security update
- added patches
  CVE-2019-11039 [bsc#1138173]
  + php-CVE-2019-11039.patch
  CVE-2019-11040 [bsc#1138172]
  + php-CVE-2019-11040.patch
Version: 7.2.5-4.32.1
* Mon May 13 2019 pgajdos@suse.com
- security update
- added patches
  CVE-2019-11036 [bsc#1134322]
  + php-CVE-2019-11036.patch
* Mon Apr 29 2019 pgajdos@suse.com
- security update
- added patches
  CVE-2019-11034 [bsc#1132838]
  + php-CVE-2019-11034.patch
  CVE-2019-11035 [bsc#1132837]
  + php-CVE-2019-11035.patch
* Wed Mar 20 2019 pgajdos@suse.com
- security update
- added patches
  CVE-2019-9637 [bsc#1128892]
  + php-CVE-2019-9637.patch
  CVE-2019-9675 [bsc#1128886]
  + php-CVE-2019-9675.patch
  CVE-2019-9638 [bsc#1128889], CVE-2019-9639 [bsc#1128887]
  + php-CVE-2019-9638,9639.patch
  CVE-2019-9640 [bsc#1128883]
  + php-CVE-2019-9640.patch
* Fri Mar 15 2019 pgajdos@suse.com
- upstream bug #41631 is already fixed [bsc#1129032]
- deleted sources
  - README.default_socket_timeout (not needed)
* Mon Mar 11 2019 pgajdos@suse.com
- security update
  * CVE-2019-9024 [bsc#1126821]
    + php-CVE-2019-9024.patch
  * CVE-2019-9020 [bsc#1126711]
    + php-CVE-2019-9020.patch
  * CVE-2018-20783 [bsc#1127122]
    + php-CVE-2018-20783.patch
  * CVE-2019-9021 [bsc#1126713]
    + php-CVE-2019-9021.patch
  * CVE-2019-9022 [bsc#1126827]
    + php-CVE-2019-9022.patch
  * CVE-2019-9023 [bsc#1126823]
    + php-CVE-2019-9023.patch
  * CVE-2019-9641 [bsc#1128722]
    + php-CVE-2019-9641.patch
* Tue Mar 05 2019 pgajdos@suse.com
- asan_build: build ASAN included
- debug_build: build more suitable for debugging
* Wed Dec 19 2018 mpluskal@suse.com
- Enable testsuite during build time and save log to subpackage
   testresults (boo#1119396)
* Mon Dec 10 2018 pgajdos@suse.com
- add security patch of imap extension, which is currently disabled
  * CVE-2018-19935 [bsc#1118832]
    + php-CVE-2018-19935.patch
* Wed Sep 19 2018 pgajdos@suse.com
- security update
  * CVE-2018-17082 [bsc#1108753]
    + php-CVE-2018-17082.patch
* Mon Sep 17 2018 pgajdos@suse.com
- reenable php7-dba support of Berkeley DB [bsc#1108554]
* Tue Aug 28 2018 pgajdos@suse.com
- align patch names:
  php7-CVE-2018-14851.patch -> php-CVE-2018-14851.patch
  php7-CVE-2017-9120.patch -> php-CVE-2017-9120.patch
  php7-CVE-2018-1000222.patch -> php-CVE-2018-1000222.patch
* Mon Aug 27 2018 pgajdos@suse.com
- security update:
  * CVE-2018-1000222 [bsc#1105434]
    + php-CVE-2018-1000222.patch
* Sat Aug 04 2018 pgajdos@suse.com
- security update
  * CVE-2018-14851 [bsc#1103659]
    + php-CVE-2018-14851.patch
  * CVE-2017-9120 [bsc#1103661]
    + php-CVE-2017-9120.patch
* Tue Jun 26 2018 pgajdos@suse.com
- security update
  * CVE-2018-12882 [bsc#1099098]
    + php-CVE-2018-12882.patch
* Tue May 15 2018 pgajdos@suse.com
- main package requires wwwrun:www user [bsc#1093025]
* Thu May 10 2018 pgajdos@suse.com
- better workaround for [bsc#1089487]: build mod_phpN.so
  instead of libphpN.so
* Wed May 09 2018 pgajdos@suse.com
- rename freetype-pkgconfig.patch to php7-freetype-pkgconfig.patch
  to align with the rest of patch names
* Mon May 07 2018 idonmez@suse.com
- Add freetype-pkgconfig.patch to fix build with new Freetype:
  use pkg-config to find Freetype libraries
* Mon Apr 30 2018 pgajdos@suse.com
- updated to 7.2.5: This is a security release which also contains
  several minor bug fixes.
  http://php.net/ChangeLog-7.php#7.2.5
* Thu Apr 19 2018 pgajdos@suse.com
- build-test.sh: generic spec file name