summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorStanislav Malyshev <stas@php.net>2020-09-29 10:09:33 -0700
committerStanislav Malyshev <stas@php.net>2020-09-29 10:09:33 -0700
commitae95d06f68768054fa3c4986d4cda24aca275541 (patch)
tree3c5cc5d105123364359a04995c3f3edc315b99b1
parentb5cb999e7fc7d669c6a0c5d28c549f7862c9f41d (diff)
downloadphp-git-ae95d06f68768054fa3c4986d4cda24aca275541.tar.gz
[ci skip] Add 7.3.23 security fixes to NEWS
-rw-r--r--NEWS6
1 files changed, 6 insertions, 0 deletions
diff --git a/NEWS b/NEWS
index a090a64eee..214c5ac342 100644
--- a/NEWS
+++ b/NEWS
@@ -37,6 +37,8 @@ PHP NEWS
. Fixed bug #80048 (Bug #69100 has not been fixed for Windows). (cmb)
. Fixed bug #80049 (Memleak when coercing integers to string via variadic
argument). (Nikita)
+ . Fixed bug #79699 (PHP parses encoded cookie names so malicious `__Host-`
+ cookies can be sent). (CVE-2020-7070) (Stas)
- Calendar:
. Fixed bug #80007 (Potential type confusion in unixtojd() parameter parsing).
@@ -52,6 +54,10 @@ PHP NEWS
. Fixed bug #79825 (opcache.file_cache causes SIGSEGV when custom opcode
handlers changed). (SammyK)
+- OpenSSL:
+ . Fixed bug #79601 (Wrong ciphertext/tag in AES-CCM encryption for a 12
+ bytes IV). (CVE-2020-7069) (Jakub Zelenka)
+
- PDO:
. Fixed bug #80027 (Terrible performance using $query->fetch on queries with
many bind parameters (Matteo)