Home / mailings [USN-7645-1] PHP vulnerabilities
Posted on 18 July 2025
Ubuntu Security==========================================================================Ubuntu Security Notice USN-7645-1
July 17, 2025
php7.0, php7.2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in PHP.
Software Description:
- php7.2: HTML-embedded scripting language interpreter
- php7.0: HTML-embedded scripting language interpreter
Details:
It was discovered that PHP incorrectly parsed certain HTTP response
headers. An attacker could possibly use this issue to cause incorrect
MIME type parsing which could result in unexpected behavior.
(CVE-2025-1217)
It was discovered that PHP did not properly validate certain HTTP
headers. An attacker could possibly use this issue to perform an HTTP
request smuggling attack. (CVE-2025-1734)
It was discovered that PHP did not properly validate certain HTTP
headers. An attacker could possibly use this issue to prevent certain
headers from being sent which could result in a denial of service or
other unexpected behavior. (CVE-2025-1736)
It was discovered that PHP incorrectly performed URL truncation. An
attacker could possibly use this issue to specially craft a URL that
would result in unintended redirections or a denial of service.
(CVE-2025-1861)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
libapache2-mod-php7.2 7.2.24-0ubuntu0.18.04.17+esm8
Available with Ubuntu Pro
libphp7.2-embed 7.2.24-0ubuntu0.18.04.17+esm8
Available with Ubuntu Pro
php7.2-cgi 7.2.24-0ubuntu0.18.04.17+esm8
Available with Ubuntu Pro
php7.2-cli 7.2.24-0ubuntu0.18.04.17+esm8
Available with Ubuntu Pro
php7.2-fpm 7.2.24-0ubuntu0.18.04.17+esm8
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libapache2-mod-php7.0 7.0.33-0ubuntu0.16.04.16+esm15
Available with Ubuntu Pro
libphp7.0-embed 7.0.33-0ubuntu0.16.04.16+esm15
Available with Ubuntu Pro
php7.0-cgi 7.0.33-0ubuntu0.16.04.16+esm15
Available with Ubuntu Pro
php7.0-cli 7.0.33-0ubuntu0.16.04.16+esm15
Available with Ubuntu Pro
php7.0-fpm 7.0.33-0ubuntu0.16.04.16+esm15
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7645-1
CVE-2025-1217, CVE-2025-1734, CVE-2025-1736, CVE-2025-1861
--===============7039636947225335265==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature