Your message dated Sat, 03 Jul 2021 15:19:52 +0000
with message-id <[email protected]>
and subject line Bug#990575: fixed in php8.0 8.0.8-1
has caused the Debian Bug report #990575,
regarding php8.0: CVE-2021-21704 CVE-2021-21705
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
990575: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=990575
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: php8.0
Version: 8.0.7-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for php8.0, they are
fixed in 8.0.8 upstream.
CVE-2021-21704[0]:
| PHP: firebird issues
CVE-2021-21705[1]:
| PHP: SSRF bypass in FILTER_VALIDATE_URL
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2021-21704
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21704
[1] https://security-tracker.debian.org/tracker/CVE-2021-21705
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21705
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: php8.0
Source-Version: 8.0.8-1
Done: Ondřej Surý <[email protected]>
We believe that the bug you reported is fixed in the latest version of
php8.0, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Ondřej Surý <[email protected]> (supplier of updated php8.0 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 01 Jul 2021 17:25:46 +0200
Source: php8.0
Architecture: source
Version: 8.0.8-1
Distribution: unstable
Urgency: medium
Maintainer: Debian PHP Maintainers <[email protected]>
Changed-By: Ondřej Surý <[email protected]>
Closes: 990575
Changes:
php8.0 (8.0.8-1) unstable; urgency=medium
.
* New upstream version 8.0.8 (Closes: #990575)
+ CVE-2021-21705: SSRF bypass in FILTER_VALIDATE_URL
+ CVE-2021-21704: Stack buffer overflow in firebird_info_cb
+ CVE-2021-21704: SIGSEGV in firebird_handle_doer
+ CVE-2021-21704: SIGSEGV in firebird_stmt_execute
+ CVE-2021-21704: Crash while parsing blob data in firebird_fetch_blob
Checksums-Sha1:
1760371c403d04ed81630e89287feaeca302e926 5656 php8.0_8.0.8-1.dsc
a3799800e0f25474ce4125789afccba5c2877e0e 10674548 php8.0_8.0.8.orig.tar.xz
7be5ba620f360c83e0aa5671014cbda22fa54394 866 php8.0_8.0.8.orig.tar.xz.asc
58182dc578e4ab2796eee1acf9706b5fb4582928 64364 php8.0_8.0.8-1.debian.tar.xz
479d004496839e65c8aca8e6869923fd220323dd 31837 php8.0_8.0.8-1_amd64.buildinfo
Checksums-Sha256:
ea61fa5bb2067f51d948b15ecfaf0cda18c37c48bb1015339d35a36bd430d633 5656
php8.0_8.0.8-1.dsc
dc1668d324232dec1d05175ec752dade92d29bb3004275118bc3f7fc7cbfbb1c 10674548
php8.0_8.0.8.orig.tar.xz
64129c26bb229c8198a3369a16552d4b28ef16bd6ca25fc46c963fd7370d511e 866
php8.0_8.0.8.orig.tar.xz.asc
8a044dca2cea686c2b36599998502e590b4e5703c6e6000fa10fc9702237508d 64364
php8.0_8.0.8-1.debian.tar.xz
be83d75edcdfe630a352a8f2c20b7291c3515c1e98986320244e5c65b404703d 31837
php8.0_8.0.8-1_amd64.buildinfo
Files:
bec1d9fa65dc2d40eaa04e4fd6dbc333 5656 php optional php8.0_8.0.8-1.dsc
ff8897b914cb8de9d218bbae877decc7 10674548 php optional php8.0_8.0.8.orig.tar.xz
7cb0329e7db8cc5c7d3985325f5b0124 866 php optional php8.0_8.0.8.orig.tar.xz.asc
842d45806006e817cd6dce2466e39213 64364 php optional
php8.0_8.0.8-1.debian.tar.xz
e3bcfc05a18c413f74dc04eef95fb310 31837 php optional
php8.0_8.0.8-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEEw2Gx4wKVQ+vGJel9g3Kkd++uWcIFAmDge7NfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEMz
NjFCMUUzMDI5NTQzRUJDNjI1RTk3RDgzNzJBNDc3RUZBRTU5QzIACgkQg3Kkd++u
WcLaKRAAq0X4cmrRBeCqOTsXssmjKfy/GHjxQ9UY1o4OgQjSOPQegZSXegZP30fG
zbZznDxtQAeVReio45hkVsBLVgU73M1MPyiH/KVCwf0dq8i2XDESonvpakVVmBG1
yIDSBa7zkN6ofW/cLlktzpZsQICs03Vl8e6XlDvP6nz7Q92uVC/jQjTK1VXN7vD/
hISFW2daD8+mq5ajYpW0o+Ak6fdjVqRSurniaJSJMNTcdeaycRvYdg0NePnGOCRj
3+BPFrDzs+e95nz6KZbIbGPKPvI7CalX1MX7N8kgKuAhoPs0HL85J4C9xulOTnth
wp6Ozb6/TuCgZqDEFQVygvbe7xo9nQNb4TGcv+3aQ4hSRU3X1Jgu7cLCWgNpKU0t
FoGPKSvpo9FJwWMAX1DbqcPuNcqr9UTSmZSJYCbxY7XbgudHvNW/x5RmLCqCpYAM
8vnYYJY/R0drMUIM6RE1XqGHM93d3oHUTaCdfSOVcVr2HsYnine14DmuoOzznI3B
T2vcSGHVl+3bN2gN6ldWrsA6w2PZxJaeTQFM5bsi/xmLSMm2/pRMCkU0ILdkueeu
gQzM/pNbxlLYbmWbOiRdN+jpYSbuonD3ItbXt9CW+97x92jRNSOJdG7wwKh5KL2n
HybJcJlMITUW/Frz+ECcdgRKAgqtnWe7yfQ3B8McJdpsWGJl01M=
=z7Io
-----END PGP SIGNATURE-----
--- End Message ---