-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4992-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso October 25, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php7.4 CVE ID : CVE-2021-21703 Debian Bug : 997003 An out-of-bounds read and write flaw was discovered in the PHP-FPM code, which could result in escalation of privileges from local unprivileged user to the root user. For the stable distribution (bullseye), this problem has been fixed in version 7.4.25-1+deb11u1. We recommend that you upgrade your php7.4 packages. For the detailed security status of php7.4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php7.4 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmF3EQhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Sirg/9FEi2498AwrLJFd38x/N9F3SndRQXFEyHFoi8vBW7HEurAbPqjLodWCqU ltk+AkOVWS8D1qRYAb8HM8ZUxF6KXZsV6rOQ4W6Gh5qX1I3pIt6LZBWO7ez/Sh8w QTGGPdmrP+Gr8RoTgKHOHxgNc8kgV7gAygdp+ImhylutXHJkwZNnhOmJjRjnzaQy nEH5mPsTTT5YS2W5a0qjQoTK44oGPHZDLq6KtZ6kdwdW9y5L4cToyghYfjw206HD rLlcMoBi7LmQfXm6Ssqi6NmTMNQjyPWKWaBmolRFPhod4T3FMxxWJ21zKpAd3ezp T+LKXlIGXNfgECbZG2xc0045WKPL5RXHKnPrFtfoXQu6PkClrm2PChJHJ9KEGKmx hWCBl5q+V2+jJSbpRsUsKOiTZ7IqphyvF5kqleUrFg85ReNSWUDbG/bzB6WORwdC OF0uCQK5nzwHqhp3i3St61jYUdjCe2bstjcZHjiw5X5o2v5EOC0aLHufiDmtaq2G 7vMHGnrd3RHRMA2aPd62xee0o6jAhycmyRr6u4X9BFgoNWxlD57gK2RuH4MC+Wb5 wUBo74Fy74Z+Bw4ynXR6tHz7rHPvwpRC+7hDATEcEBqE4t72Z4fedxYciLOMwo7Z TZuFZoR3ACOKiOx4z0gnA/X3OG9I49kQrCuTltecdCm3LIs+l+8= =kDjO -----END PGP SIGNATURE-----