USN-8336-1: PHP vulnerabilities
Source: Ubuntu
Published:
<p>Aleksey Solovev and Nikita Sveshnikov discovered that PHP improperly handled NUL bytes when preparing SQL queries in the PDO Firebird driver. An attacker could possibly use this issue to perform SQL injection attacks. ( CVE-2025-14179 ) It was discovered that PHP incorrectly handled certain encod