-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 18 Dec 2025 22:19:25 +0100
Source: php8.4
Architecture: source
Version: 8.4.16-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian PHP Maintainers <team+pkg-php@tracker.debian.org>
Changed-By: Ondřej Surý <ondrej@debian.org>
Changes:
php8.4 (8.4.16-1~deb13u1) trixie-security; urgency=high
.
* New upstream version 8.4.16
+ [CVE-2025-14180]: Fixed GHSA-8xr5-qppj-gvwj (PDO quoting result null
deref).
+ [CVE-2025-14178]: Fixed GHSA-h96m-rvf9-jgm2 (Heap buffer overflow in
array_merge()).
+ [CVE-2025-14177]: Fixed GHSA-3237-qqm7-mfv7 (Information Leak of
Memory in getimagesize).
Checksums-Sha1:
4b43f11e2956564076f983210c9223e76f219bfa 5375 php8.4_8.4.16-1~deb13u1.dsc
ce889c85b4a5ff4a663c7de51929c6451f637c49 13660836 php8.4_8.4.16.orig.tar.xz
3280a493b9c574ea70b0ba2df8bb569b14e1ff4d 74268 php8.4_8.4.16-1~deb13u1.debian.tar.xz
9fc8542df8a9290769bdfb2837f0ed89423fabc0 33985 php8.4_8.4.16-1~deb13u1_amd64.buildinfo
Checksums-Sha256:
30c72812c426f53c39cd91f3f55711eb32654609b7cb0be5b92bdb3d24f981cd 5375 php8.4_8.4.16-1~deb13u1.dsc
f66f8f48db34e9e29f7bfd6901178e9cf4a1b163e6e497716dfcb8f88bcfae30 13660836 php8.4_8.4.16.orig.tar.xz
9ad0fafdc77150798374f521a95c1432a0a8def2c6710fcb46aae6476dd4267f 74268 php8.4_8.4.16-1~deb13u1.debian.tar.xz
254a5a3708c0bfb1724f981be28c9c3e52c4618c533341315b421071611fb297 33985 php8.4_8.4.16-1~deb13u1_amd64.buildinfo
Files:
a5c44316f58108baacfae3e60e1510f8 5375 php optional php8.4_8.4.16-1~deb13u1.dsc
caaccf12223032ec302322d2079af264 13660836 php optional php8.4_8.4.16.orig.tar.xz
575a0c6d7d588b7a9d8be4459be1286e 74268 php optional php8.4_8.4.16-1~deb13u1.debian.tar.xz
bf92fab7e125d4df0cc292ef34cb71c0 33985 php optional php8.4_8.4.16-1~deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEEw2Gx4wKVQ+vGJel9g3Kkd++uWcIFAmlEel5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEMz
NjFCMUUzMDI5NTQzRUJDNjI1RTk3RDgzNzJBNDc3RUZBRTU5QzIACgkQg3Kkd++u
WcLE2g/8Chfx2/lbf3XO5va3UAZxmFcj1kCHzAb1HCeusEQoJc+8io9ZHlZx07uj
NczyfW34q11IPJEioD85D5I8NwoB90NcKBiXYSdvgTQSjtEv1rc4iymO9t/BN9AI
2pPnlvJCiawoYN7K3t6FWTmGcSPzMVqzGM/L3g7jZwv5fyLQaipHJaD1oMlF4eXq
qY0X0LBIIsyjQ50WyAY8PhyzS6z57+dmWLk052ooGRAylKFMOlf6IRBP8Qfd2V3d
L9IewD46hx/kxW6NN1lgrkpk1lGqlYfmy1hvoSprsluVXuvIF6qhmfPb32Ag/637
aUYJrlThC/VpQS8hZAc+6t8ytm0v9QwICY6jURmOyfVbwA61bMUc8l+t+2w8Ye/E
K/VRxhm1/CqZhbgjDkInk2Sk1W3ZAOmvvS0gNgY+5H2Jm/pOh4Ueg+7aOcA+HkRD
T/jbCp7MAVovfbDkgRNBtfyMmkAYSUNaVqteWLbFdvNrab1odolgVKyplP/Bzw9K
QMPf4mX2EKHRjDcgJNU2wLrXVD+Le6JP0hlytTmC4ECt/pPGZsyD1GmHbehVANIt
YiPCfoyse274lW76PnsQhvVHK3+CwX610BGoTRUQuXUVl7pE/+JcSFMa/6uU/NMi
6xMtRtY1KrJj7Q13Rs56zDXLapum7IU5yCRHZeQhsnQHfA+l7o4=
=8sbE
-----END PGP SIGNATURE-----