-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 17 Jun 2024 15:33:14 +0200 Source: php8.2 Binary: php8.2 php8.2-xsl Architecture: all Version: 8.2.20-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all Build Daemon (x86-csail-02) Changed-By: Ondřej Surý Description: php8.2 - server-side, HTML-embedded scripting language (metapackage) php8.2-xsl - XSL module for PHP (dummy) Changes: php8.2 (8.2.20-1~deb12u1) bookworm-security; urgency=high . * New upstream version 8.2.20 + [CVE-2024-4577]: Bypass of CVE-2012-1823, Argument Injection in PHP-CGI. + [CVE-2024-5458]: Filter bypass in filter_var FILTER_VALIDATE_URL. + [CVE-2024-5585]: Bypass of CVE-2024-1874. * Fix GH-14480: Method visibility issue introduced in version 8.2.20. Checksums-Sha1: 19f9ecc0060bb1f1016a154ce15b4a39f7a815d4 38820 php8.2-xsl_8.2.20-1~deb12u1_all.deb 6c96aeb0101e2a3ce6e9eb529144dba608e6b869 13984 php8.2_8.2.20-1~deb12u1_all-buildd.buildinfo db217aaab654a1f1228f4af7af8b4fc18e8b47b8 39152 php8.2_8.2.20-1~deb12u1_all.deb Checksums-Sha256: b15590f4f280647c956401a3be7477cefc5f7401b8c046b4c92342d362ea13ae 38820 php8.2-xsl_8.2.20-1~deb12u1_all.deb 90299987f1045cfe9b714a02b0e8f6e78265742d7e5e36240516b9b3886a3a4c 13984 php8.2_8.2.20-1~deb12u1_all-buildd.buildinfo 5c22b837c1eb6ae6f6eb81f962091bb701a72b423521ae5d8e96d5f39edb15b1 39152 php8.2_8.2.20-1~deb12u1_all.deb Files: 320b399d9e99f31138bf49774eec0fe7 38820 php optional php8.2-xsl_8.2.20-1~deb12u1_all.deb 0c79c055a6797995b4ace5ee4db75d10 13984 php optional php8.2_8.2.20-1~deb12u1_all-buildd.buildinfo 9c8f8ce430419fbf39a687c40d8c5308 39152 php optional php8.2_8.2.20-1~deb12u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEzcbx6nIE/ydHa1FFigL77i1GSVkFAmZxP7EACgkQigL77i1G SVlzUg//TcZuz908p8lty8ymDDX8TGhMJ1EeZJKoJL3DVsbrwsYSIbtjwsS6RoeE XMR3a/rcCgZAVlxmGDBXa/B1Nd480VvHQ7vbQIkfvKGtcm1SsFzDrvUME6+Nw1Qf 6X9ukyNuo+a73lT/2+eyHao3HzeCOPcyuW/ZNvStwoaHIK4WNTps2A5i2DJmbELu fmTMuLBnHz5dwfxa7Xw9Ypgc4XS14ggewJY2y6h40kGqY8zRoAfjITNKZtZ7kXPl 6na+r0158c4Z3iqnBWFF0ruO7ys0XKZB+qBnNMHz4Wbb9ce3jP4GEbuXRt/vhHGa DAqZlNK89uOabEdqom7NplGhJ0j+Dsw6dfoYauKqnNYEtwmTdrR9t5Q3qZSeoxio tC6/yFrLu3M/NeO9A8+IOerLzS9QSwI0XySHLxiz3L0l5/SZXELHyxjLzs0ZhVks 8R/xjHBuhj9/3Sf80E8phDPyy2ytrE0/lyBQbHf33WKJh7jMduQH98DgHYdeZB6c 8yMIYlyuT5s9eofrxdmY7vYqRksj5WwED92IJECeoFF3kGGPM40ojNB8iKYVXe9j Btv2WFyF0LLbpFxal3l4S2c82Z8K46BQpbjgOeEUmKmL5EouO83ZgITqsOmoaAgg l+dp4ayFuv0vKlgkYRkurGmO+OXHBuh1qqNB9JO1+/rEMmlcqzY= =nnAZ -----END PGP SIGNATURE-----