-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 08 Mar 2019 10:01:24 +0000 Source: php7.0 Binary: libapache2-mod-php7.0 libphp7.0-embed php7.0 php7.0-cgi php7.0-cli php7.0-dev php7.0-fpm php7.0-phpdbg php7.0-xsl php7.0-odbc php7.0-readline php7.0-recode php7.0-sqlite3 php7.0-tidy php7.0-xml php7.0-sybase php7.0-gd php7.0-mcrypt php7.0-zip php7.0-common php7.0-intl php7.0-snmp php7.0-curl php7.0-json php7.0-pgsql php7.0-mbstring php7.0-enchant php7.0-opcache php7.0-imap php7.0-gmp php7.0-mysql php7.0-bcmath php7.0-soap php7.0-dba php7.0-interbase php7.0-xmlrpc php7.0-pspell php7.0-bz2 php7.0-ldap Architecture: source Version: 7.0.33-0+deb9u3 Distribution: stretch-security Urgency: medium Maintainer: Debian PHP Maintainers Changed-By: Ondřej Surý Description: libapache2-mod-php7.0 - server-side, HTML-embedded scripting language (Apache 2 module) libphp7.0-embed - HTML-embedded scripting language (Embedded SAPI library) php7.0 - server-side, HTML-embedded scripting language (metapackage) php7.0-bcmath - Bcmath module for PHP php7.0-bz2 - bzip2 module for PHP php7.0-cgi - server-side, HTML-embedded scripting language (CGI binary) php7.0-cli - command-line interpreter for the PHP scripting language php7.0-common - documentation, examples and common module for PHP php7.0-curl - CURL module for PHP php7.0-dba - DBA module for PHP php7.0-dev - Files for PHP7.0 module development php7.0-enchant - Enchant module for PHP php7.0-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php7.0-gd - GD module for PHP php7.0-gmp - GMP module for PHP php7.0-imap - IMAP module for PHP php7.0-interbase - Interbase module for PHP php7.0-intl - Internationalisation module for PHP php7.0-json - JSON module for PHP php7.0-ldap - LDAP module for PHP php7.0-mbstring - MBSTRING module for PHP php7.0-mcrypt - libmcrypt module for PHP php7.0-mysql - MySQL module for PHP php7.0-odbc - ODBC module for PHP php7.0-opcache - Zend OpCache module for PHP php7.0-pgsql - PostgreSQL module for PHP php7.0-phpdbg - server-side, HTML-embedded scripting language (PHPDBG binary) php7.0-pspell - pspell module for PHP php7.0-readline - readline module for PHP php7.0-recode - recode module for PHP php7.0-snmp - SNMP module for PHP php7.0-soap - SOAP module for PHP php7.0-sqlite3 - SQLite3 module for PHP php7.0-sybase - Sybase module for PHP php7.0-tidy - tidy module for PHP php7.0-xml - DOM, SimpleXML, WDDX, XML, and XSL module for PHP php7.0-xmlrpc - XMLRPC-EPI module for PHP php7.0-xsl - XSL module for PHP (dummy) php7.0-zip - Zip module for PHP Changes: php7.0 (7.0.33-0+deb9u3) stretch-security; urgency=medium . * Pull security fixes from https://github.com/Microsoft/php-src, a shared effort by Remi Collet and Anatol Belski to keep up with security issues in PHP 5.6.40 after EOL. * Security Issues Fixed: + Core: - Fixed bug #77630 (rename() across the device may allow unwanted access during processing). + EXIF: - Fixed bug #77509 (Uninitialized read in exif_process_IFD_in_TIFF). - Fixed bug #77540 (Invalid Read on exif_process_SOFn). - Fixed bug #77563 (Uninitialized read in exif_process_IFD_in_MAKERNOTE). - Fixed bug #77659 (Uninitialized read in exif_process_IFD_in_MAKERNOTE). + PHAR: - Fixed bug #77396 (Null Pointer Dereference in phar_create_or_parse_filename). - Fixed bug #77586 (phar_tar_writeheaders_int() buffer overflow). + SPL: - Fixed bug #77431 (openFile() silently truncates after a null byte). Checksums-Sha1: 01d8e20fadb7eafc16280971c181eb7ecaa577c3 5790 php7.0_7.0.33-0+deb9u3.dsc 386004218de9816d1a3f5ffde7da5d279c26db59 75408 php7.0_7.0.33-0+deb9u3.debian.tar.xz cdd459dd041a0e02994dc968240baa82035c5651 36017 php7.0_7.0.33-0+deb9u3_amd64.buildinfo Checksums-Sha256: bcce5f44b07692a0152152a47b037c57c58ad881435c9e759e5f95e058d2a7af 5790 php7.0_7.0.33-0+deb9u3.dsc f79aad773571d6d52047e217970af2b763d232fa877479d7159615de55b77820 75408 php7.0_7.0.33-0+deb9u3.debian.tar.xz 7339ebc06bf3ebecbe407a034f42967d477a6dea7dd14503c126e894dde896eb 36017 php7.0_7.0.33-0+deb9u3_amd64.buildinfo Files: 9cea7fb5d886dd8165f819181e0f59f5 5790 php optional php7.0_7.0.33-0+deb9u3.dsc 84c1ba2ebd930a4d30fb96948d478652 75408 php optional php7.0_7.0.33-0+deb9u3.debian.tar.xz 3c80aa29a3f8a552cd692c954e51d958 36017 php optional php7.0_7.0.33-0+deb9u3_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEw2Gx4wKVQ+vGJel9g3Kkd++uWcIFAlyCZHRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEMz NjFCMUUzMDI5NTQzRUJDNjI1RTk3RDgzNzJBNDc3RUZBRTU5QzIACgkQg3Kkd++u WcJmpxAAjyXpRYFhnRIax9ybCRG+LIOcYr3VmjooH9dyhjySEf6Ptn2maBRdw8si /fF2T6Q+VMoxm70kFYtLStFtlb5i5N/ng6e7zJlpIkc6B1F7rqt13foljX827ngG f4YA8QqSMbSPrsCi6v61VyRag3by5SOG57rRe5+CsZ/lavs2hJqFdQo5i9zCanQd t/a5IxZzdYjxONXyrKo4Yw5s+lP1k78KO4/kWHw7aT87Swh+H0pMRHqT4fiiK4xa k4vJcXuJeB4hw1aQG/iUTCeXYXzskLiC9h3+YSPxiPkOBHQm80BehGOQyOp6JBPB tuJv4XbzZNCpQuHp5FoLjmWQLoG1v8y1r2guua1wsQilfQ1VGN/v1dxwKMdCucxQ rVc6rBcQZBKurUNqQVVFMkFI1ct7/032bWpAVVZ5UaJbUUTEkjOaloUX5H/A1dM9 k/V0ecXh9aJYSZ93rSwXE7GE4WPeHUrxHhSEcF/lgwRLEbmKVYKw+wLCDO8jeiT8 BZvHui8XZlLSdpjO5P/JMGZWQo25tlLy07t8fSTsTVm2AOsuSCkQxOexuxlC/j6/ a9TuBx1epOKRm7Gl7uF/AzLKvxLff4g80LNJa3IyqHE9CSHFzetHMUj/XMvBkiLO GDZ1NZZ7E6uPldzFvfdHv0BT6a6hd3eu0xYOz2UIcOBG7Px9pEc= =EHvx -----END PGP SIGNATURE-----