Skip to content

Commit de4f7f9

Browse files
committed
Update NEWS
1 parent 0ba5229 commit de4f7f9

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

NEWS

+7
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,13 @@ PHP NEWS
22
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
33
?? ??? ????, PHP 8.1.28
44

5+
- Standard:
6+
. Fixed bug GHSA-pc52-254m-w9w7 (Command injection via array-ish $command
7+
parameter of proc_open). (CVE-2024-1874) (Jakub Zelenka)
8+
. Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to
9+
partial CVE-2022-31629 fix). (CVE-2024-2756) (nielsdos)
10+
. Fixed bug GHSA-h746-cjrr-wfmr (password_verify can erroneously return true,
11+
opening ATO risk). (CVE-2024-3096) (Jakub Zelenka)
512

613
21 Dec 2023, PHP 8.1.27
714

0 commit comments

Comments
 (0)