INFSA-2025:7489: php security update

Information about definition

Identificator: INFSA-2025:7489

Type: security

Release date: 2025-07-15 19:25:38 UTC

Information about package

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.

Vulnerabilities description

  • CVE-2024-11235

    A flaw was found in PHP. This vulnerability allows remote code execution via a crafted code path involving the __set magic method or the null coalescing assignment (??=) operator, in combination with exception handling. Attackers can trigger a use-after-free condition by controlling the memory layout through specially crafted inputs.

  • CVE-2025-1217

    A flaw was found in PHP. This vulnerability allows misinterpretation of HTTP response headers, potentially leading to incorrect usage of headers, MIME types, and other response attributes via incorrect parsing of folded headers in the HTTP request module.

  • CVE-2025-1219

    A flaw was found in PHP's DOM and SimpleXML extensions. This vulnerability allows incorrect parsing of a redirected HTTP resource via improper content-type header handling.

  • CVE-2025-1734

    A flaw was found in PHP. This vulnerability allows applications to accept invalid headers via malformed HTTP headers missing a colon (:), which may confuse applications into processing them as valid headers.

  • CVE-2025-1736

    A flaw was found in PHP. This vulnerability allows certain headers to be either not sent or misinterpreted due to insufficient validation of the end-of-line characters via user-supplied headers.

  • CVE-2025-1861

    A flaw was found in PHP. This vulnerability allows incorrect URL truncation and redirection to the wrong location via HTTP redirect handling due to a limited location buffer size.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 8.1 no information
NIST — CVE-2025-1217
no information 3.7 no information
NIST — CVE-2025-1219
no information 3.7 no information
NIST — CVE-2025-1734
no information 3.7 no information
NIST — CVE-2025-1736
no information 3.7 no information
NIST — CVE-2025-1861
no information 5.3 no information
Critical, important, moderate, low

Updated packages