Bug#943468: php-fpm: CVE-2019-11043: Vulnerability in PHP-FPM Could Lead to Remote Code Execution on nginx

2019-12-01 Thread Ivo De Decker
Hi, On Mon, Nov 11, 2019 at 09:07:55PM +0100, Ondřej Surý wrote: > The Debian stable has been fixed shortly after the new version was updated. > There’s no strong security update guarantee for unstable and testing. From the > security team FAQ: > > > If you want to have a secure (and stable)

Bug#943468: php-fpm: CVE-2019-11043: Vulnerability in PHP-FPM Could Lead to Remote Code Execution on nginx

2019-11-11 Thread Ondřej Surý
The Debian stable has been fixed shortly after the new version was updated. There’s no strong security update guarantee for unstable and testing. From the security team FAQ: > If you want to have a secure (and stable) server you are strongly encouraged > to stay with stable. Ondrej -- Ondřej

Bug#943468: php-fpm: CVE-2019-11043: Vulnerability in PHP-FPM Could Lead to Remote Code Execution on nginx

2019-11-11 Thread Alex
Hi, PHP published a fixed version (7.3.11) before this CVE went public. Can you please package and upload that version? If that is not possible, can you please at least explain in the bug report why fixing this (pretty serious) bug is not possible at the moment? That might attract some