Fedora 40 : php (2025-4e7e2c40e0)

medium Nessus Plugin ID 233171


The remote Fedora host is missing one or more security updates.


The remote Fedora 40 host has a package installed that is affected by multiple vulnerabilities as referenced in the FEDORA-2025-4e7e2c40e0 advisory.

**PHP version 8.3.19** (13 Mar 2025)


* Fixed bug [GH-17398](https://github.com/php/php-src/issues/17398) (bcmul memory leak). (SakiTakamachi)


* Fixed bug [GH-17623](https://github.com/php/php-src/issues/17623) (Broken stack overflow detection for variable compilation). (ilutov)
* Fixed bug [GH-17618](https://github.com/php/php-src/issues/17618) (UnhandledMatchError does not take zend.exception_ignore_args=1 into account). (timwolla)
* Fix fallback paths in fast_long_{add,sub}_function. (nielsdos)
* Fixed bug [GH-17718](https://github.com/php/php-src/issues/17718) (Calling static methods on an interface that has `__callStatic` is allowed). (timwolla)
* Fixed bug [GH-17797](https://github.com/php/php-src/issues/17797) (zend_test_compile_string crash on invalid script path). (David Carlier)
* Fixed [GHSA-rwp7-7vc6-8477](https://github.com/php/php-src/security/advisories/GHSA-rwp7-7vc6-8477) (Reference counting in php_request_shutdown causes Use-After-Free). (**CVE-2024-11235**) (ilutov)


* Fixed bug [GH-17847](https://github.com/php/php-src/issues/17847) (xinclude destroys live node).


* Fix FFI Parsing of Pointer Declaration Lists. (davnotdev)


* Fixed bug [GH-17643](https://github.com/php/php-src/issues/17643) (FPM with httpd ProxyPass encoded PATH_INFO env). (Jakub Zelenka)


* Fixed bug [GH-17772](https://github.com/php/php-src/issues/17772) (imagepalettetotruecolor crash with memory_limit=2M). (David Carlier)


* Fixed bug [GH-17704](https://github.com/php/php-src/issues/17704) (ldap_search fails when $attributes contains a non-packed array with numerical keys). (nielsdos, 7u83)


* Fixed [GHSA-wg4p-4hqh-c3g9](https://github.com/php/php-src/security/advisories/GHSA-wg4p-4hqh-c3g9) (Reocurrence of php#72714). (nielsdos)
* Fixed [GHSA-p3x9-6h7p-cgfc](https://github.com/php/php-src/security/advisories/GHSA-p3x9-6h7p-cgfc) (libxml streams use wrong `content-type` header when requesting a redirected resource).
(**CVE-2025-1219**) (timwolla)


* Fixed bug [GH-17503](https://github.com/php/php-src/issues/17503) (Undefined float conversion in mb_convert_variables). (cmb)


* Fixed bug [GH-17654](https://github.com/php/php-src/issues/17654) (Multiple classes using same trait causes function JIT crash). (nielsdos)
* Fixed bug [GH-17577](https://github.com/php/php-src/issues/17577) (JIT packed type guard crash).
(nielsdos, Dmitry)
* Fixed bug [GH-17899](https://github.com/php/php-src/issues/17899) (zend_test_compile_string with invalid path when opcache is enabled). (David Carlier)
* Fixed bug [GH-17868](https://github.com/php/php-src/issues/17868) (Cannot allocate memory with tracing JIT). (nielsdos)


* Fixed [GH-17837](https://github.com/php/php-src/issues/17837) ()::getColumnMeta() on unexecuted statement segfaults). (cmb)
* Fix cycle leak in sqlite3 setAuthorizer(). (nielsdos)


* Fixed bug [GH-17808](https://github.com/php/php-src/issues/17808): PharFileInfo refcount bug. (nielsdos)


* Partially fixed bug [GH-17387](https://github.com/php/php-src/issues/17387) (Trivial crash in phpdbg lexer). (nielsdos)
* Fix memory leak in phpdbg calling registered function. (nielsdos)


* Fixed bug [GH-15902](https://github.com/php/php-src/issues/15902) (Core dumped in ext/reflection/php_reflection.c). (DanielEScherzer)


* Fixed bug php#72666 (stat cache clearing inconsistent between file:// paths and plain paths). (Jakub Zelenka)


* Fixed bug [GH-17650](https://github.com/php/php-src/issues/17650) (realloc with size 0 in user_filters.c). (nielsdos)
* Fix memory leak on overflow in _php_stream_scandir(). (nielsdos)
* Fixed [GHSA-hgf54-96fm-v528](https://github.com/php/php-src/security/advisories/GHSA-hgf54-96fm-v528) (Stream HTTP wrapper header check might omit basic auth header). (**CVE-2025-1736**) (Jakub Zelenka)
* Fixed [GHSA-52jp-hrpf-2jff](https://github.com/php/php-src/security/advisories/GHSA-52jp-hrpf-2jff) (Stream HTTP wrapper truncate redirect location to 1024 bytes). (**CVE-2025-1861**) (Jakub Zelenka)
* Fixed [GHSA-pcmh-g36c-qc44](https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36c-qc44) (Streams HTTP wrapper does not fail for headers without colon). (**CVE-2025-1734**) (Jakub Zelenka)
* Fixed [GHSA-v8xr-gpvj-cx9g](https://github.com/php/php-src/security/advisories/GHSA-v8xr-gpvj-cx9g) (Header parser of `http` stream wrapper does not handle folded headers). (**CVE-2025-1217**) (Jakub Zelenka)


* Fixed bug [GH-17745](https://github.com/php/php-src/issues/17745) (zlib extension incorrectly handles object arguments). (nielsdos)
* Fix memory leak when encoding check fails. (nielsdos)
* Fix zlib support for large files. (nielsdos)

Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.


Update the affected php package.

See Also


Plugin Details

Severity: Medium

ID: 233171

File Name: fedora_2025-4e7e2c40e0.nasl

Version: 1.1

Type: local

Agent: unix

Published: 3/21/2025

Updated: 3/21/2025

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information


Risk Factor: Medium

Score: 5.2


Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2025-1219


Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:40, p-cpe:/a:fedoraproject:fedora:php

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 3/12/2025

Vulnerability Publication Date: 3/12/2025

Reference Information

CVE: CVE-2024-11235, CVE-2025-1217, CVE-2025-1219, CVE-2025-1734, CVE-2025-1736, CVE-2025-1861

FEDORA: 2025-4e7e2c40e0

IAVA: 2025-A-0183