* Thu Jul 09 2020 pgajdos@suse.com
- Use /run/php-fpm instead of /run/php
- modified sources
% php-fpm.tmpfiles.d
* Thu May 14 2020 suse+build@de-korte.org
- updated to 7.4.6: This is a security release which also contains
several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.6
* Wed May 13 2020 pgajdos@suse.com
- added patches
build fixes in SLE12
+ php7-arm-build-fixes.patch
* Tue May 12 2020 pgajdos@suse.com
- added to SLE-12 [jsc#SLE-12474]
* Tue May 12 2020 pgajdos@suse.com
- spec file usable under SLE12 again and better prepared for
phpM -> phpMN transition
* Mon May 11 2020 pgajdos@suse.com
- added to SLE-15-SP2 [jsc#SLE-12482], including fixes for:
CVE-2020-7063 [bsc#1165289]
CVE-2020-7062 [bsc#1165280]
CVE-2019-11046, CVE-2019-11050, CVE-2019-11047, CVE-2019-11045
* Tue Apr 14 2020 suse+build@de-korte.org
- updated to 7.4.5: This is a security release which also contains
several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.5
* Thu Apr 02 2020 pgajdos@suse.com
- remove Berkeley DB Database support [jsc#SLE-12210]
* Fri Mar 20 2020 pgajdos@suse.com
- build firebird extension in any case
* Tue Mar 17 2020 suse+build@de-korte.org
- updated to 7.4.4: This is a security release which also contains
several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.4
* Thu Mar 12 2020 mliska@suse.cz
- Enable LTO as it works now (boo#1133275).
* Wed Feb 19 2020 suse+build@de-korte.org
- updated to 7.4.3: This is a security release which also contains
several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.3
* Mon Feb 10 2020 pgajdos@suse.com
- add %apache_rex_deps
* Thu Jan 23 2020 suse+build@de-korte.org
- updated to 7.4.2: This is a security release which also contains
several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.2
* Wed Dec 18 2019 suse+build@de-korte.org
- updated to 7.4.1: This is a security release which also contains
several bug fixes. See https://www.php.net/ChangeLog-7.php#7.4.1
- deleted patches
- php-fix-mysqlnd-compression-library.patch
- php-fpm-service-fails-to-start.patch
* Tue Dec 10 2019 pgajdos@suse.com
- php7-devel requires glibc-devel, libxml2-devel, pcre2-devel
again
* Thu Dec 05 2019 suse+build@de-korte.org
- relax systemd restrictions for FPM as they were too strict in
some applications
- change leftover Requires php7-<extension> to php-<extension>
- remove external libraries from -devel subpackage
- added patches
+ php-fpm-service-fails-to-start.patch
* Thu Nov 28 2019 suse+build@de-korte.org
- update to 7.4.0:
* Typed Properties
* Arrow Functions
* Limited Return Type Covariance and Argument Type Contravariance
* Unpacking Inside Arrays
* Numeric Literal Separator
* Weak References
* Allow Exceptions from __toString()
* Opcache Preloading
* The interbase and wddx extensions are removed and now
available through PECL
* PEAR is now packaged separately in php7-pear source package
(https://externals.io/message/103977)
* See https://www.php.net/ChangeLog-7.php#7.4.0 for a complete
list of changes
- deleted patches
- php-suse-addons.tar.bz
- php-systzdata-v18.patch
- added patches
+ php-fix-mysqlnd-compression-library.patch
+ php-systzdata-v19.patch
+ mod_php7.conf
- modified files/patches
% php-no-build-date.patch
% php-systemd-unit.patch
% php7.keyring (use keys of the PHP-7.4 release managers)
% php7.rpmlintrc
Version: 7.4.33-150400.4.55.1
* Wed Jan 07 2026 pgajdos@suse.com
- security update
- added patches
CVE-2025-14178 [bsc#1255711], heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE
* php7-CVE-2025-14178.patch
* Fri Jul 11 2025 pgajdos@suse.com
- security update
- added patches
CVE-2025-1220 [bsc#1246167], unprocessed null bytes in hostnames can lead to SSRF
+ php7-CVE-2025-1220.patch
CVE-2025-1735 [bsc#1246146], pgsql extension does not properly handle errors within escape functions
+ php7-CVE-2025-1735.patch
CVE-2025-6491 [bsc#1246148], NULL pointer dereference when processing a SoapVar with a fully qualified name that is longer than 2G
+ php7-CVE-2025-6491.patch
* Tue Mar 18 2025 pgajdos@suse.com
- security update
- modified patches
% php-php-config.patch (-p1)
% php-phpize.patch (-p1)
- added patches
fix CVE-2024-11235 [bsc#1239666], Reference counting in php_request_shutdown causes Use-After-Free
+ php7-CVE-2024-11235.patch
fix CVE-2025-1217 [bsc#1239664], Header parser of `http` stream wrapper does not handle folded headers
+ php7-CVE-2025-1217.patch
fix CVE-2025-1734 [bsc#1239668], Streams HTTP wrapper does not fail for headers with invalid name and no colon
+ php7-CVE-2025-1734.patch
fix CVE-2025-1736 [bsc#1239670], Stream HTTP wrapper header check might omit basic auth header
+ php7-CVE-2025-1736.patch
fix CVE-2025-1861 [bsc#1239669], Stream HTTP wrapper truncate redirect location to 1024 bytes
+ php7-CVE-2025-1861.patch
fix CVE-2025-1219 [bsc#1239667], libxml streams use wrong `content-type` header when requesting a redirected resource
+ php8-CVE-2025-1219.patch
* Tue Nov 26 2024 pgajdos@suse.com
- security update
- added patches
fix CVE-2024-11233 [bsc#1233702], single-byte buffer overread due to missing bounds check when processing input with convert.quoted-printable-decode filters
+ php7-CVE-2024-11233.patch
fix CVE-2024-11234 [bsc#1233703], configuring streams with a proxy and the 'request_fulluri' context option might allow for CRLF injection in URIs
+ php7-CVE-2024-11234.patch
fix CVE-2024-8929 [bsc#1233651], In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests ...
+ php7-CVE-2024-8929.patch
* Fri Oct 11 2024 pgajdos@suse.com
- security update
- added patches
fix CVE-2024-8925 [bsc#1231360], erroneous parsing of multipart form data in HTTP POST requests leads to legitimate data not being processed
+ php7-CVE-2024-8925.patch
fix CVE-2024-8927 [bsc#1231358], cgi.force_redirect configuration is bypassable due to an environment variable collision
+ php7-CVE-2024-8927.patch
fix CVE-2024-9026 [bsc#1231382], pollution of worker output logs in PHP-FPM
+ php7-CVE-2024-9026.patch
* Tue Jun 11 2024 pgajdos@suse.com
- security update
- added patches
fix CVE-2024-5458 [bsc#1226073], filter bypass in filter_var FILTER_VALIDATE_URL
+ php7-CVE-2024-5458.patch
* Fri Apr 19 2024 pgajdos@suse.com
- security update
- added patches
fix CVE-2024-2756 [bsc#1222857], host/secure cookie bypass due to partial fix
+ php7-CVE-2024-2756.patch
fix CVE-2024-3096 [bsc#1222858], password_verify can erroneously return true, opening ATO risk
+ php7-CVE-2024-3096.patch
* Tue Jan 16 2024 pgajdos@suse.com
- ensure we are building against openssl-1_1
* Wed Aug 23 2023 pgajdos@suse.com
- security update
- added patches
fix CVE-2023-3823 [bsc#1214106], XML loading external entity without being enabled
+ php7-CVE-2023-3823.patch
fix CVE-2023-3824 [bsc#1214103], buffer overflows in phar_dir_read()
+ php7-CVE-2023-3824.patch
* Thu Jun 15 2023 pgajdos@suse.com
- security update
- added patches
fix CVE-2023-3247 [bsc#1212349], Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP
+ php7-CVE-2023-3247.patch
* Tue Mar 21 2023 pgajdos@suse.com
- security update
- added patches
fix CVE-2022-4900 [bsc#1209537], potential buffer overflow via PHP_CLI_SERVER_WORKERS environment variable
+ php7-CVE-2022-4900.patch
* Tue Mar 14 2023 pgajdos@suse.com
- fix potential buffer overflow [bsc#1208199]
- modified patches
% php-systzdata-v19.patch (refreshed)
* Mon Mar 06 2023 pgajdos@suse.com
- ensure extension=mysqlnd will be called before extension=mysqli
[bsc#1205162]
* Fri Feb 17 2023 pgajdos@suse.com
- security update
- added patches
fix CVE-2023-0568 [bsc#1208366], NULL byte off-by-one in php_check_specific_open_basedir
+ php7-CVE-2023-0568.patch
fix CVE-2023-0662 [bsc#1208367], DoS vulnerability when parsing multipart request body
+ php7-CVE-2023-0662.patch
https://github.com/php/php-src/commit/a92acbad873a05470af1a47cb785a18eadd827b5, relates to CVE-2023-0567 [bsc#1208388]
+ php7-crypt-possible-buffer-overread.patch
* Mon Jan 09 2023 pgajdos@suse.com
- security update
- added patches
fix CVE-2022-31631 [bsc#1206958], Due to an integer overflow PDO:quote() may return unquoted string
+ php7-CVE-2022-31631.patch
* Fri Jun 17 2022 pgajdos@suse.com
- security update
- added patches
fix CVE-2022-31626 [bsc#1200628], buffer overflow via user-supplied password when using pdo_mysql extension with mysqlnd driver
+ php7-CVE-2022-31626.patch
* Fri Jun 10 2022 pgajdos@suse.com
- security update
- added patches
fix CVE-2021-21707 [bsc#1193041], special character breaks path in xml parsing
+ php7-CVE-2021-21707.patch
Version: 7.2.5-4.61.1
* Thu Aug 13 2020 pgajdos@suse.com
- security update
- added patches
fix CVE-2020-7068 [bsc#1175223], Use of freed hash key in the phar_parse_zipfile function
+ php7-CVE-2020-7068.patch
* Tue Aug 04 2020 pgajdos@suse.com
- do not install outdated README.SUSE [bsc#1174010]
* Thu Jul 09 2020 pgajdos@suse.com
- do not install %{_tmpfilesdir}, %{_tmpfilesdir}/php-fpm.conf in
test favour
* Mon Jul 06 2020 daniel.molkentin@suse.com
- added tmpfiles.d for php-fpm to provide a base base for a socket
(boo#1173786)
Version: 7.2.5-4.58.2
* Mon May 25 2020 pgajdos@suse.com
- security update
- added patches
fix CVE-2019-11048 [bsc#1171999], supplying overly long filenames or field names if HTTP file uploads are allowed could lead to exhausting disk space on the server
+ php7-CVE-2019-11048.patch
* Tue Apr 07 2020 pgajdos@suse.com
- security update
- added patches
fix CVE-2020-7064 [bsc#1168326], read one byte of uninitialized memory via malicious data
+ php7-CVE-2020-7064.patch
fix CVE-2020-7066 [bsc#1168352], URL truncation if the URL contains zero (\0) character
+ php7-CVE-2020-7066.patch
* Mon Mar 02 2020 pgajdos@suse.com
- security update
- added patches
fix CVE-2020-7062 [bsc#1165280], null pointer dereference when using file upload functionality under specific circumstances
+ php7-CVE-2020-7062.patch
fix CVE-2020-7063 [bsc#1165289], creating PHAR archive using PharData:buildFromIterator() function will add files with default permissions
+ php7-CVE-2020-7063.patch
* Wed Feb 05 2020 pgajdos@suse.com
- security update
- added patches
CVE-2020-7059 [bsc#1162629]
+ php7-CVE-2020-7059.patch
CVE-2020-7060 [bsc#1162632]
+ php7-CVE-2020-7060.patch
Version: 7.2.5-4.32.1
* Mon May 13 2019 pgajdos@suse.com
- security update
- added patches
CVE-2019-11036 [bsc#1134322]
+ php-CVE-2019-11036.patch
* Mon Apr 29 2019 pgajdos@suse.com
- security update
- added patches
CVE-2019-11034 [bsc#1132838]
+ php-CVE-2019-11034.patch
CVE-2019-11035 [bsc#1132837]
+ php-CVE-2019-11035.patch
* Wed Mar 20 2019 pgajdos@suse.com
- security update
- added patches
CVE-2019-9637 [bsc#1128892]
+ php-CVE-2019-9637.patch
CVE-2019-9675 [bsc#1128886]
+ php-CVE-2019-9675.patch
CVE-2019-9638 [bsc#1128889], CVE-2019-9639 [bsc#1128887]
+ php-CVE-2019-9638,9639.patch
CVE-2019-9640 [bsc#1128883]
+ php-CVE-2019-9640.patch
* Fri Mar 15 2019 pgajdos@suse.com
- upstream bug #41631 is already fixed [bsc#1129032]
- deleted sources
- README.default_socket_timeout (not needed)
* Mon Mar 11 2019 pgajdos@suse.com
- security update
* CVE-2019-9024 [bsc#1126821]
+ php-CVE-2019-9024.patch
* CVE-2019-9020 [bsc#1126711]
+ php-CVE-2019-9020.patch
* CVE-2018-20783 [bsc#1127122]
+ php-CVE-2018-20783.patch
* CVE-2019-9021 [bsc#1126713]
+ php-CVE-2019-9021.patch
* CVE-2019-9022 [bsc#1126827]
+ php-CVE-2019-9022.patch
* CVE-2019-9023 [bsc#1126823]
+ php-CVE-2019-9023.patch
* CVE-2019-9641 [bsc#1128722]
+ php-CVE-2019-9641.patch
* Tue Mar 05 2019 pgajdos@suse.com
- asan_build: build ASAN included
- debug_build: build more suitable for debugging
* Wed Dec 19 2018 mpluskal@suse.com
- Enable testsuite during build time and save log to subpackage
testresults (boo#1119396)
* Mon Dec 10 2018 pgajdos@suse.com
- add security patch of imap extension, which is currently disabled
* CVE-2018-19935 [bsc#1118832]
+ php-CVE-2018-19935.patch
* Wed Sep 19 2018 pgajdos@suse.com
- security update
* CVE-2018-17082 [bsc#1108753]
+ php-CVE-2018-17082.patch
* Mon Sep 17 2018 pgajdos@suse.com
- reenable php7-dba support of Berkeley DB [bsc#1108554]
* Tue Aug 28 2018 pgajdos@suse.com
- align patch names:
php7-CVE-2018-14851.patch -> php-CVE-2018-14851.patch
php7-CVE-2017-9120.patch -> php-CVE-2017-9120.patch
php7-CVE-2018-1000222.patch -> php-CVE-2018-1000222.patch
* Mon Aug 27 2018 pgajdos@suse.com
- security update:
* CVE-2018-1000222 [bsc#1105434]
+ php-CVE-2018-1000222.patch
* Sat Aug 04 2018 pgajdos@suse.com
- security update
* CVE-2018-14851 [bsc#1103659]
+ php-CVE-2018-14851.patch
* CVE-2017-9120 [bsc#1103661]
+ php-CVE-2017-9120.patch
* Tue Jun 26 2018 pgajdos@suse.com
- security update
* CVE-2018-12882 [bsc#1099098]
+ php-CVE-2018-12882.patch
* Tue May 15 2018 pgajdos@suse.com
- main package requires wwwrun:www user [bsc#1093025]
* Thu May 10 2018 pgajdos@suse.com
- better workaround for [bsc#1089487]: build mod_phpN.so
instead of libphpN.so
* Wed May 09 2018 pgajdos@suse.com
- rename freetype-pkgconfig.patch to php7-freetype-pkgconfig.patch
to align with the rest of patch names
* Mon May 07 2018 idonmez@suse.com
- Add freetype-pkgconfig.patch to fix build with new Freetype:
use pkg-config to find Freetype libraries
* Mon Apr 30 2018 pgajdos@suse.com
- updated to 7.2.5: This is a security release which also contains
several minor bug fixes.
http://php.net/ChangeLog-7.php#7.2.5
* Thu Apr 19 2018 pgajdos@suse.com
- build-test.sh: generic spec file name