[Bug 1843591] Re: Security issues related to php7.2.19

2019-10-29 Thread Thomas Ward
** Changed in: nginx Status: Fix Released => Invalid ** No longer affects: nginx -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1843591 Title: Security issues related to php7.2.19 To manage

[Bug 1843591] Re: Security issues related to php7.2.19

2019-10-29 Thread Thomas Kopp
** Changed in: nginx Status: Invalid => Fix Released ** Changed in: php7.2 (Ubuntu) Status: Incomplete => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1843591 Title: Sec

[Bug 1843591] Re: Security issues related to php7.2.19

2019-10-29 Thread Thomas Kopp
Can be closed, cause it's fixed due to the update to php7.2.24 ** No longer affects: php-fpm -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1843591 Title: Security issues related to php7.2.19 To ma

[Bug 1843591] Re: Security issues related to php7.2.19

2019-10-27 Thread Thomas Kopp
** No longer affects: nginx (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1843591 Title: Security issues related to php7.2.19 To manage notifications about this bug go to: https://bugs.lau

[Bug 1843591] Re: Security issues related to php7.2.19

2019-10-26 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: nginx (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1843591 Title: Secu

[Bug 1843591] Re: Security issues related to php7.2.19

2019-10-26 Thread Thomas Ward
This has to do with the NGINX configs used by Nextcloud, without evidence that this directly affects NGINX default configurations, there's nothing for us to do here for NGINX. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bug

[Bug 1843591] Re: Security issues related to php7.2.19

2019-10-26 Thread Thomas Ward
This bug has *nothing* to do with NGINX, and everything to do with PHP specifically. There is no embedded PHP in NGINX. Marking as "Invalid" against NGINX, this needs to be fixed in PHP *only* and not NGINX. ** Project changed: nginx => nginx (Ubuntu) ** Changed in: nginx (Ubuntu) Status

[Bug 1843591] Re: Security issues related to php7.2.19

2019-10-26 Thread Thomas Kopp
With php7.2-fpm Module ** Also affects: nginx Importance: Undecided Status: New ** Bug watch added: bugs.php.net/ #78599 http://bugs.php.net/bug.php?id=78599 ** Also affects: php-fpm via http://bugs.php.net/bug.php?id=78599 Importance: Unknown Status: Unknown -- You r

[Bug 1843591] Re: Security issues related to php7.2.19

2019-10-25 Thread Oliver Kennedy
CVE-2019-11043 seems to be a more serious code injection issue affecting this version. It appears to be fixed in 7.2.24 (https://nextcloud.com/blog/urgent- security-issue-in-nginx-php-fpm/) ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-11043 -- You received this bug notifica

Re: [Bug 1843591] Re: Security issues related to php7.2.19

2019-09-12 Thread Nish Aravamudan
PHP has a MRE generally (Microrelease Exception) and gets regular updates in the security and updates pocket via upstream dotreleases. On Thu, Sep 12, 2019 at 6:41 AM Paride Legovini < paride.legov...@canonical.com> wrote: > Thanks for your report. Security updates are usually done by patching >

[Bug 1843591] Re: Security issues related to php7.2.19

2019-09-12 Thread Paride Legovini
Thanks for your report. Security updates are usually done by patching the released package with the specific fix needed to address the problem, trying to minimize changes in behavior and the regression risk. New releases of software packages are normally not backported to existing Ubuntu releases,

[Bug 1843591] Re: Security issues related to php7.2.19

2019-09-11 Thread Gilmar Pereira
Will ubuntu package php7.2.19 be upgraded to php7.2.22? If yes, when it will be available on APT? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1843591 Title: Security issues related to php7.2.19 T