ELA-457-1 php5 security update

multiple vulnerabilities

2021-07-15
Packagephp5
Version5.6.40+dfsg-0+deb8u14
Related CVEs CVE-2019-9675 CVE-2020-7068 CVE-2020-7071 CVE-2021-21702 CVE-2021-21704 CVE-2021-21705


Several vulnerabilities were discovered in php5, a server-side, HTML-embedded scripting language. An attacker could cause denial of service (DoS), memory corruption and potentially execution of arbitrary code, and server-side request forgery (SSRF) bypass.



For Debian 8 jessie, these problems have been fixed in version 5.6.40+dfsg-0+deb8u14.

We recommend that you upgrade your php5 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.