Information on source package php7.0

Available versions

ReleaseVersion
stretch7.0.33-0+deb9u16
stretch (security)7.0.33-0+deb9u12

Open issues

BugstretchDescription
CVE-2017-8923vulnerable (no DSA, ignored)The zend_string_extend function in Zend/zend_string.h in PHP through 7 ...
CVE-2017-7272vulnerable (no DSA, ignored)PHP through 7.1.11 enables potential SSRF in applications that accept ...
CVE-2017-7189vulnerable (no DSA, ignored)main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsocko ...

Open unimportant issues

BugstretchDescription
CVE-2019-6977vulnerablegdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka ...
CVE-2017-9120vulnerablePHP 7.x through 7.1.5 allows remote attackers to cause a denial of ser ...
CVE-2017-9119vulnerableThe i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 all ...
CVE-2017-9118vulnerablePHP 7.1.5 has an Out of bounds access in php_pcre_replace_impl via a c ...
CVE-2015-9253vulnerableAn issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before ...

Resolved issues

BugDescription
TEMP-0000000-F26C42Type confusion vulnerability in WDDX packet deserialization
TEMP-0000000-EA5272NULL Pointer Dereference in phar_tar_setupmetadata()
TEMP-0000000-D591DCInteger overflow in iptcembed()
TEMP-0000000-B391CAexec functions ignore length but look for NULL termination
TEMP-0000000-A9D025Crash on bad SOAP request
CVE-2023-3824In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* bef ...
CVE-2023-3823In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* be ...
CVE-2023-3247In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before ...
CVE-2023-0662In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3 ...
CVE-2023-0568In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3 ...
CVE-2023-0567In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3 ...
CVE-2022-37454The Keccak XKCP SHA-3 reference implementation before fdc6fef has an i ...
CVE-2022-31631
CVE-2022-31630In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imagelo ...
CVE-2022-31629In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability en ...
CVE-2022-31628In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompresso ...
CVE-2022-31627In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as fi ...
CVE-2022-31626In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x belo ...
CVE-2022-31625In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x belo ...
CVE-2022-4900A vulnerability was found in PHP where setting the environment variabl ...
CVE-2021-21708In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x belo ...
CVE-2021-21707In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below ...
CVE-2021-21706In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below ...
CVE-2021-21705In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below ...
CVE-2021-21704In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below ...
CVE-2021-21703In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 a ...
CVE-2021-21702In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below ...
CVE-2020-7071In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when ...
CVE-2020-7070In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below ...
CVE-2020-7069In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below ...
CVE-2020-7068In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below ...
CVE-2020-7067In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below ...
CVE-2020-7066In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below ...
CVE-2020-7065In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using ...
CVE-2020-7064In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below ...
CVE-2020-7063In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below ...
CVE-2020-7062In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below ...
CVE-2020-7061In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extrac ...
CVE-2020-7060When using certain mbstring functions to convert multibyte encodings, ...
CVE-2020-7059When using fgetss() function to read data with stripping tags, in PHP ...
CVE-2019-18218cdf_read_property_info in cdf.c in file through 5.37 does not restrict ...
CVE-2019-13224A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 a ...
CVE-2019-11050When PHP EXIF extension is parsing EXIF information from an image, e.g ...
CVE-2019-11049In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplyin ...
CVE-2019-11048In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below ...
CVE-2019-11047When PHP EXIF extension is parsing EXIF information from an image, e.g ...
CVE-2019-11046In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP ...
CVE-2019-11045In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP ...
CVE-2019-11044In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Wi ...
CVE-2019-11043In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below ...
CVE-2019-11042When PHP EXIF extension is parsing EXIF information from an image, e.g ...
CVE-2019-11041When PHP EXIF extension is parsing EXIF information from an image, e.g ...
CVE-2019-11040When PHP EXIF extension is parsing EXIF information from an image, e.g ...
CVE-2019-11039Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.3 ...
CVE-2019-11038When using the gdImageCreateFromXbm() function in the GD Graphics Libr ...
CVE-2019-11036When processing certain files, PHP EXIF extension in versions 7.1.x be ...
CVE-2019-11035When processing certain files, PHP EXIF extension in versions 7.1.x be ...
CVE-2019-11034When processing certain files, PHP EXIF extension in versions 7.1.x be ...
CVE-2019-9675An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3. ...
CVE-2019-9641An issue was discovered in the EXIF component in PHP before 7.1.27, 7. ...
CVE-2019-9640An issue was discovered in the EXIF component in PHP before 7.1.27, 7. ...
CVE-2019-9639An issue was discovered in the EXIF component in PHP before 7.1.27, 7. ...
CVE-2019-9638An issue was discovered in the EXIF component in PHP before 7.1.27, 7. ...
CVE-2019-9637An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and ...
CVE-2019-9024An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x ...
CVE-2019-9023An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x ...
CVE-2019-9022An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, ...
CVE-2019-9021An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x ...
CVE-2019-9020An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x ...
CVE-2018-20783In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2. ...
CVE-2018-19935ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote atta ...
CVE-2018-19518University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_o ...
CVE-2018-19396ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attac ...
CVE-2018-19395ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attacke ...
CVE-2018-17082The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x ...
CVE-2018-15132An issue was discovered in ext/standard/link_win32.c in PHP before 5.6 ...
CVE-2018-14884An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.1 ...
CVE-2018-14883An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1 ...
CVE-2018-14851exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, ...
CVE-2018-12882exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allo ...
CVE-2018-10549An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1 ...
CVE-2018-10548An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1 ...
CVE-2018-10547An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36 ...
CVE-2018-10546An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1 ...
CVE-2018-10545An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1 ...
CVE-2018-7584In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and ...
CVE-2018-5712An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1 ...
CVE-2018-5711gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP bef ...
CVE-2017-16642In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an e ...
CVE-2017-12934ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x ...
CVE-2017-12933The finish_nested_data function in ext/standard/var_unserializer.re in ...
CVE-2017-12932ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x ...
CVE-2017-11628In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a sta ...
CVE-2017-11362In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/ms ...
CVE-2017-11147In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler c ...
CVE-2017-11145In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an er ...
CVE-2017-11144In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the o ...
CVE-2017-11143In PHP before 5.6.31, an invalid free in the WDDX deserialization of b ...
CVE-2017-11142In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remot ...
CVE-2017-7890The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in th ...
CVE-2017-5340Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandle ...
CVE-2016-10712In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all o ...
CVE-2016-10397In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of vari ...
CVE-2016-10168Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) bef ...
CVE-2016-10167The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Li ...
CVE-2016-10162The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x befo ...
CVE-2016-10161The object_common1 function in ext/standard/var_unserializer.c in PHP ...
CVE-2016-10160Off-by-one error in the phar_parse_pharfile function in ext/phar/phar. ...
CVE-2016-10159Integer overflow in the phar_parse_pharfile function in ext/phar/phar. ...
CVE-2016-10158The exif_convert_any_to_int function in ext/exif/exif.c in PHP before ...
CVE-2016-9936The unserialize implementation in ext/standard/var.c in PHP 7.x before ...
CVE-2016-9935The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5. ...
CVE-2016-9934ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remo ...
CVE-2016-9933Stack consumption vulnerability in the gdImageFillToBorder function in ...
CVE-2016-9138PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modifica ...
CVE-2016-9137Use-after-free vulnerability in the CURLFile implementation in ext/cur ...
CVE-2016-7568Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD ...
CVE-2016-7480The SplObjectStorage unserialize implementation in ext/spl/spl_observe ...
CVE-2016-7479In all versions of PHP 7, during the unserialization process, resizing ...
CVE-2016-7478Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x befo ...
CVE-2016-7418The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5. ...
CVE-2016-7417ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceed ...
CVE-2016-7416ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x bef ...
CVE-2016-7414The ZIP signature-verification feature in PHP before 5.6.26 and 7.x be ...
CVE-2016-7413Use-after-free vulnerability in the wddx_stack_destroy function in ext ...
CVE-2016-7412ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before ...
CVE-2016-7411ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles objec ...
CVE-2016-7134ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a l ...
CVE-2016-7133Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabl ...
CVE-2016-7132ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remo ...
CVE-2016-7131ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remo ...
CVE-2016-7130The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6 ...
CVE-2016-7129The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5. ...
CVE-2016-7128The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before ...
CVE-2016-7127The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and ...
CVE-2016-7126The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6. ...
CVE-2016-7125ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips ...
CVE-2016-7124ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7. ...
CVE-2016-6297Integer overflow in the php_stream_zip_opener function in ext/zip/zip_ ...
CVE-2016-6296Integer signedness error in the simplestring_addn function in simplest ...
CVE-2016-6295ext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x bef ...
CVE-2016-6294The locale_accept_from_http function in ext/intl/locale/locale_methods ...
CVE-2016-6292The exif_process_user_comment function in ext/exif/exif.c in PHP befor ...
CVE-2016-6291The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP b ...
CVE-2016-6290ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7 ...
CVE-2016-6289Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_ ...
CVE-2016-6207Integer overflow in the _gdContributionsAlloc function in gd_interpola ...
CVE-2016-6128The gdImageCropThreshold function in gd_crop.c in the GD Graphics Libr ...
CVE-2016-5773php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6. ...
CVE-2016-5772Double free vulnerability in the php_wddx_process_data function in wdd ...
CVE-2016-5771spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before ...
CVE-2016-5770Integer overflow in the SplFileObject::fread function in spl_directory ...
CVE-2016-5769Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP ...
CVE-2016-5768Double free vulnerability in the _php_mb_regex_ereg_replace_exec funct ...
CVE-2016-5767Integer overflow in the gdImageCreate function in gd.c in the GD Graph ...
CVE-2016-5766Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD G ...
CVE-2016-5399The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x befor ...
CVE-2016-5385PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 ...
CVE-2016-5093The get_icu_value_internal function in ext/intl/locale/locale_methods. ...
CVE-2016-4544The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP befor ...
CVE-2016-4543The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before ...
CVE-2016-4542The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5 ...
CVE-2016-4541The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in ...
CVE-2016-4540The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c i ...
CVE-2016-4539The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5. ...
CVE-2016-4538The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6 ...
CVE-2016-4537The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6 ...
CVE-2016-4346Integer overflow in the str_pad function in ext/standard/string.c in P ...
CVE-2016-4345Integer overflow in the php_filter_encode_url function in ext/filter/s ...
CVE-2016-4344Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in P ...
CVE-2016-4343The phar_make_dirstream function in ext/phar/dirstream.c in PHP before ...
CVE-2016-4342ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and ...
CVE-2016-4073Multiple integer overflows in the mbfl_strcut function in ext/mbstring ...
CVE-2016-4072The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x ...
CVE-2016-4071Format string vulnerability in the php_snmp_error function in ext/snmp ...
CVE-2016-4070Integer overflow in the php_raw_url_encode function in ext/standard/ur ...
CVE-2016-3185The make_http_soap_request function in ext/soap/php_http.c in PHP befo ...
CVE-2016-3132Double free vulnerability in the SplDoublyLinkedList::offsetSet functi ...
CVE-2016-3078Multiple integer overflows in php_zip.c in the zip extension in PHP be ...
CVE-2016-3074Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or li ...
CVE-2016-2554Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5. ...
CVE-2016-1904Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7. ...
CVE-2016-1903The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolatio ...
CVE-2015-8994An issue was discovered in PHP 5.x and 7.x, when the configuration use ...
CVE-2015-8880Double free vulnerability in the format printer in PHP 7.x before 7.0. ...
CVE-2015-8879The odbc_bindcols function in ext/odbc/php_odbc.c in PHP before 5.6.12 ...
CVE-2015-8877The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graph ...
CVE-2015-8876Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and ...
CVE-2015-8874Stack consumption vulnerability in GD in PHP before 5.6.12 allows remo ...
CVE-2015-8867The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in P ...
CVE-2015-8865The file_check_mem function in funcs.c in file before 5.23, as used in ...
CVE-2015-8617Format string vulnerability in the zend_throw_or_error function in Zen ...
CVE-2015-8616Use-after-free vulnerability in the Collator::sortWithSortKeys functio ...
CVE-2013-7456gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1 ...

Security announcements

DSA / DLADescription
ELA-934-1php7.0 - security update
ELA-873-1php7.0 - security update
ELA-848-1php7.0 - security update
ELA-775-1php7.0 - security update
DLA-2794-1php7.0 - security update
DLA-2708-1php7.0 - security update
DLA-2397-1php7.0 - security update
DLA-2345-1php7.0 - security update
DSA-4717-1php7.0 - security update
DSA-4628-1php7.0 - security update
DSA-4552-1php7.0 - security update
DSA-4529-1php7.0 - security update
DSA-4403-1php7.0 - security update
DSA-4398-1php7.0 - security update
DSA-4353-1php7.0 - security update
DSA-4240-1php7.0 - security update
DSA-4080-1php7.0 - security update

Search for package or bug name: Reporting problems