-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 SUMMARY cPanel, L.L.C. has updated RPMs for EasyApache 4 with PHP versions 7.1.31, 7.2.21, and 7.3.8. This release addresses vulnerabilities related to CVE-2019-11041 and CVE-2019-11042, plus other vulnerabilities with no number currently assigned. We strongly encourage all PHP 7.1 users to upgrade to version 7.1.31, all PHP 7.2 users to upgrade to version 7.2.21, and all PHP 7.3 users to upgrade to version 7.3.8. AFFECTED VERSIONS All versions of PHP 7.1 through 7.1.30 All versions of PHP 7.2 through 7.2.20 All versions of PHP 7.3 through 7.3.7 SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2019-11041 - MEDIUM PHP 7.1.31 Fixed bug in Exif module related to CVE-2019-11041 PHP 7.2.21 Fixed bug in Exif module related to CVE-2019-11041 PHP 7.3.8 Fixed bug in Exif module related to CVE-2019-11041 CVE-2019-11042 - MEDIUM PHP 7.1.31 Fixed bug in Exif module related to CVE-2019-11042 PHP 7.2.21 Fixed bug in Exif module related to CVE-2019-11042 PHP 7.3.8 Fixed bug in Exif module related to CVE-2019-11042 This release also contains other vulnerabilities with no CVE number currently assigned. SOLUTION cPanel, L.L.C. has released updated RPMs for EasyApache 4 on August 7, 2019, with updated versions of PHP versions 7.1.31, 7.2.21, and 7.3.8. Unless you have enabled automatic RPM updates in your cron, update your system with either yum update or WHM's Run System Update interface. REFERENCES https://nvd.nist.gov/vuln/detail/CVE-2019-11041 https://nvd.nist.gov/vuln/detail/CVE-2019-11042 https://www.php.net/ChangeLog-7.php -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEEtnCbTMb0IHf2mEGRlSG+3KvZTd8FAl1K6LQUHHNlY3VyaXR5 QGNwYW5lbC5uZXQACgkQlSG+3KvZTd+AWw//fG8LIVVcrrm0baOS11nTfrw1Yuwx Ip/qaJEH+6+Tl3kdZacTpVa1ZFNCejOboX9l0WMakTBLtV+0550V7CTc+EtMz9Au 4kTNoIcrwRlxHwqgEuAN8/J7t/BgkJFkg8tp/d4QywJsact36KdacJQZWIPP9O1H PqMJwNxOFpsEWGzrIoyoQTMtKY+ty7F+kXgpsrhKJfyT+CNKwPPtcSrQhzS/k8eK /9XWQppKmRSv8/YeLSM/wVS8YxNGAPcJ9qdwbXj4P9lXPrDtrRK/QVTcqeLKF/Rv MVRYehj9k6E4Cd89/38qxix3jn0rpJ0hDNFgs1myRyE/1IFReL/CrxgZxHwv3MsS YvGUADImlRoygqXUxqESb6UIwnjO371OiopTDItNK3hARq6eE6ve2v8i4ZrL1Fiu gd5vILeahGiyCmwotmRof9U7+lR3J55AF62c3JNIBVRyUD3OtNAkZM2JtzEhKt2O rlZkl28OPKARAKqghbVlM6/racfRp86z8stHWkbLHJvKmvEwFpMq1eY5lZ0CR4ih QyAN9mBp/1G68wUqSnqj0oMKG+hiFVn6slW1se/qoIKu7oJUePgIfOd9aJTgSYth OlBipGmvKUsk6gqjNhhE8ne4OCzETV8nrETFA/Kq2yaBTijvanDn+yTIZRRyMfPi jPu98O0lzcdAGwk= =047b -----END PGP SIGNATURE-----