Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2014-1768

Опубликовано: 30 окт. 2014
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2014-1768: php53 security update (IMPORTANT)

[5.3.3-26]

  • fileinfo: fix out-of-bounds read in elf note headers. CVE-2014-3710

[5.3.3-25]

  • xmlrpc: fix out-of-bounds read flaw in mkgmtime() CVE-2014-3668
  • core: fix integer overflow in unserialize() CVE-2014-3669
  • exif: fix heap corruption issue in exif_thumbnail() CVE-2014-3670

Обновленные пакеты

Oracle Linux 5

Oracle Linux ia64

php53

5.3.3-26.el5_11

php53-bcmath

5.3.3-26.el5_11

php53-cli

5.3.3-26.el5_11

php53-common

5.3.3-26.el5_11

php53-dba

5.3.3-26.el5_11

php53-devel

5.3.3-26.el5_11

php53-gd

5.3.3-26.el5_11

php53-imap

5.3.3-26.el5_11

php53-intl

5.3.3-26.el5_11

php53-ldap

5.3.3-26.el5_11

php53-mbstring

5.3.3-26.el5_11

php53-mysql

5.3.3-26.el5_11

php53-odbc

5.3.3-26.el5_11

php53-pdo

5.3.3-26.el5_11

php53-pgsql

5.3.3-26.el5_11

php53-process

5.3.3-26.el5_11

php53-pspell

5.3.3-26.el5_11

php53-snmp

5.3.3-26.el5_11

php53-soap

5.3.3-26.el5_11

php53-xml

5.3.3-26.el5_11

php53-xmlrpc

5.3.3-26.el5_11

Oracle Linux x86_64

php53

5.3.3-26.el5_11

php53-bcmath

5.3.3-26.el5_11

php53-cli

5.3.3-26.el5_11

php53-common

5.3.3-26.el5_11

php53-dba

5.3.3-26.el5_11

php53-devel

5.3.3-26.el5_11

php53-gd

5.3.3-26.el5_11

php53-imap

5.3.3-26.el5_11

php53-intl

5.3.3-26.el5_11

php53-ldap

5.3.3-26.el5_11

php53-mbstring

5.3.3-26.el5_11

php53-mysql

5.3.3-26.el5_11

php53-odbc

5.3.3-26.el5_11

php53-pdo

5.3.3-26.el5_11

php53-pgsql

5.3.3-26.el5_11

php53-process

5.3.3-26.el5_11

php53-pspell

5.3.3-26.el5_11

php53-snmp

5.3.3-26.el5_11

php53-soap

5.3.3-26.el5_11

php53-xml

5.3.3-26.el5_11

php53-xmlrpc

5.3.3-26.el5_11

Oracle Linux i386

php53

5.3.3-26.el5_11

php53-bcmath

5.3.3-26.el5_11

php53-cli

5.3.3-26.el5_11

php53-common

5.3.3-26.el5_11

php53-dba

5.3.3-26.el5_11

php53-devel

5.3.3-26.el5_11

php53-gd

5.3.3-26.el5_11

php53-imap

5.3.3-26.el5_11

php53-intl

5.3.3-26.el5_11

php53-ldap

5.3.3-26.el5_11

php53-mbstring

5.3.3-26.el5_11

php53-mysql

5.3.3-26.el5_11

php53-odbc

5.3.3-26.el5_11

php53-pdo

5.3.3-26.el5_11

php53-pgsql

5.3.3-26.el5_11

php53-process

5.3.3-26.el5_11

php53-pspell

5.3.3-26.el5_11

php53-snmp

5.3.3-26.el5_11

php53-soap

5.3.3-26.el5_11

php53-xml

5.3.3-26.el5_11

php53-xmlrpc

5.3.3-26.el5_11

Связанные уязвимости

oracle-oval
больше 10 лет назад

ELSA-2014-1767: php security update (IMPORTANT)

oracle-oval
больше 10 лет назад

ELSA-2014-1824: php security update (IMPORTANT)

ubuntu
больше 10 лет назад

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

redhat
почти 11 лет назад

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

nvd
больше 10 лет назад

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.