-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4527-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff September 19, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php7.3 CVE ID : CVE-2019-11036 CVE-2019-11039 CVE-2019-11040 CVE-2019-11041 CVE-2019-11042 Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: Missing sanitising in the EXIF extension and the iconv_mime_decode_headers() function could result in information disclosure or denial of service. For the stable distribution (buster), these problems have been fixed in version 7.3.9-1~deb10u1. We recommend that you upgrade your php7.3 packages. For the detailed security status of php7.3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php7.3 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl2D6O0ACgkQEMKTtsN8 TjYx1g/+KDaoAK5IIW5Nb6yLZjUT7JsJsb9tSD+rYLOe1A6R/6envfkPp4LuK3Tv +VNA0JQ1js/9swccoNlDUBXpxHOqzp3KeB6kEsM61WQAX+oqh7VwGhh2JnPbau35 2GKZfRzc24fc3UBqxEBY4+GfV/Th0CnVahyaaAz33Gt5N7DZHaRY71UK7MHce2ir mOHMdoPp3N5t5UxefKfsju8raluOidNkiXJlIvILnWrz5mYDOBAi2xpEQw1JIjTO mgGkCtZNU8nWV6C4tugiOnrRa03Kb6SgCd77XZRty5zoYTjSTMc75HTyvbqAKThG 44lGJEdvQDK7aW40wgQ2YWnFYKxyQOrU6kbPPkvu+IqXBsQIfJ0alZ2e/GXHrPAf RkrbFgwFoNl8KPspVCtczuxAoihTsexJk5cVs/1GqD1mIhf2ftRi5qdJaq7Jr3RZ KJd9rqkf6Us7yWjJM7ajUtdx/HCQDunEYXIoCsyfCGZC8a3FGfhnPuAFT9CpVVFu y1nQnOGlSweWFd2nUMkS/k9+O/WlAMxnz30rHX9tBpEFy5amRXgRnd2EVVZvdpo9 PQRdTBB/H8Va01JhcSO79GXvdZCeKv8f3PIlJxz4CjMyCrG07Ij3i9NgSU9Vl/oa 5zXOTwbTO2ylLoZP+ac9E/Jwg7uGaC76lNwhzlbtOBl+jg6knRo=SH4w -----END PGP SIGNATURE-----