-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 26 Oct 2021 19:51:39 +0200 Source: php7.0 Binary: libapache2-mod-php7.0 libphp7.0-embed php7.0 php7.0-cgi php7.0-cli php7.0-dev php7.0-fpm php7.0-phpdbg php7.0-xsl php7.0-intl php7.0-odbc php7.0-readline php7.0-recode php7.0-common php7.0-sqlite3 php7.0-xml php7.0-sybase php7.0-gd php7.0-mcrypt php7.0-zip php7.0-interbase php7.0-tidy php7.0-mysql php7.0-snmp php7.0-curl php7.0-json php7.0-pgsql php7.0-mbstring php7.0-enchant php7.0-opcache php7.0-imap php7.0-gmp php7.0-bcmath php7.0-soap php7.0-dba php7.0-xmlrpc php7.0-pspell php7.0-bz2 php7.0-ldap Architecture: source Version: 7.0.33-0+deb9u12 Distribution: stretch-security Urgency: high Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org> Changed-By: Sylvain Beucler <beuc@debian.org> Description: libapache2-mod-php7.0 - server-side, HTML-embedded scripting language (Apache 2 module) libphp7.0-embed - HTML-embedded scripting language (Embedded SAPI library) php7.0 - server-side, HTML-embedded scripting language (metapackage) php7.0-bcmath - Bcmath module for PHP php7.0-bz2 - bzip2 module for PHP php7.0-cgi - server-side, HTML-embedded scripting language (CGI binary) php7.0-cli - command-line interpreter for the PHP scripting language php7.0-common - documentation, examples and common module for PHP php7.0-curl - CURL module for PHP php7.0-dba - DBA module for PHP php7.0-dev - Files for PHP7.0 module development php7.0-enchant - Enchant module for PHP php7.0-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php7.0-gd - GD module for PHP php7.0-gmp - GMP module for PHP php7.0-imap - IMAP module for PHP php7.0-interbase - Interbase module for PHP php7.0-intl - Internationalisation module for PHP php7.0-json - JSON module for PHP php7.0-ldap - LDAP module for PHP php7.0-mbstring - MBSTRING module for PHP php7.0-mcrypt - libmcrypt module for PHP php7.0-mysql - MySQL module for PHP php7.0-odbc - ODBC module for PHP php7.0-opcache - Zend OpCache module for PHP php7.0-pgsql - PostgreSQL module for PHP php7.0-phpdbg - server-side, HTML-embedded scripting language (PHPDBG binary) php7.0-pspell - pspell module for PHP php7.0-readline - readline module for PHP php7.0-recode - recode module for PHP php7.0-snmp - SNMP module for PHP php7.0-soap - SOAP module for PHP php7.0-sqlite3 - SQLite3 module for PHP php7.0-sybase - Sybase module for PHP php7.0-tidy - tidy module for PHP php7.0-xml - DOM, SimpleXML, WDDX, XML, and XSL module for PHP php7.0-xmlrpc - XMLRPC-EPI module for PHP php7.0-xsl - XSL module for PHP (dummy) php7.0-zip - Zip module for PHP Changes: php7.0 (7.0.33-0+deb9u12) stretch-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * CVE-2021-21703: when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user. Checksums-Sha1: 5ae5b0dc0530cecbfcb8a477f1a55f77a647d657 5667 php7.0_7.0.33-0+deb9u12.dsc 6056faf0a451210b59b979c4b81a8ea7888a70ea 848740 php7.0_7.0.33-0+deb9u12.debian.tar.xz 48882f021db835670eded77529023d2d41782ff5 35563 php7.0_7.0.33-0+deb9u12_amd64.buildinfo Checksums-Sha256: b3085a78d7acf58acd0c1e4e9638f1bcac3822c80b301741b3b89580f4ae3db4 5667 php7.0_7.0.33-0+deb9u12.dsc 021cbb0f1e81863f26aaee724f214654ce18d7b5879b319b29f0e80d99190287 848740 php7.0_7.0.33-0+deb9u12.debian.tar.xz 078d37a17454f3e265d9594d2c4e03557cc14f3dbb786db6d1a391321524b104 35563 php7.0_7.0.33-0+deb9u12_amd64.buildinfo Files: 8b78ba5b29226f4e11a61e80c9a7ea61 5667 php optional php7.0_7.0.33-0+deb9u12.dsc d983a87f6aeb9b5d3b4e9ddb7b01dfbf 848740 php optional php7.0_7.0.33-0+deb9u12.debian.tar.xz 6d05b8a6b73d8f261102dcb3945748a0 35563 php optional php7.0_7.0.33-0+deb9u12_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmF5F0IACgkQDTl9HeUl XjD15A//bazJVZazvbSgTuYGmI5xQna9lrIaCf0RWCJiEqt4g9S8lo+ouKtQwFhX XPhqLAPNTK/LLYdtd53Z0gjMKDNT+s/77Kq1qyIcf/YYRo8FzHYKft0GRFBaNBNK RDf/4i50sVN9W86NmyoJtVhiuuLtcG0HNQlreZS02vfKHm0YAuBSqUOtVZEcBSWq uB8tZ8+E8f6dz5zGFUBlZMO8ltbawdAwZPl4R+i80eV7YUDHFpPSlDVFHLmruFuH 3VLybZ/n7owRXou9bSn7M5Xcf9iwv8EgS2misQ5vtEHuQ0vZBTH4sbr5wy6mud2Y 3jrYKP5A5hixlZgPL/aX7hbxCJ7bgzHA7/tGM51j2XfA8kA+JAMltOWZoHOiqXqH kMsIM2Zu7uqPaEGZyhaxCR4ztvMbFajZGY0i6Fk3bKtlm00XlT876Ovz68ZDaWuL if1sgpbj8hXTjfR7RKCM7IqRR4ArSuJw/Q71XNqTXgDQ6oAZ7m5UZqto17QX9tuJ IPTncb+ORp2hOG5bZSTBh6Vab4eRPCvmd+1UNhpxg2itA21tIDN/7q9qVovapwm1 Nlqe01O0PL5eZyiIPjEPyrrHCmFcsj6P13gFsyA/DPf3tcUDtyVB59GRH92fBZZo NovXJOeZvADWv5NrI7lQQ8obqmXT635u0HKp8RNT/BVaSes+g0E= =jy3h -----END PGP SIGNATURE-----