Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2015-1218

Опубликовано: 09 июл. 2015
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2015-1218: php security update (MODERATE)

[5.3.3-46]

  • fix gzfile accept paths with NUL character #1213407
  • fix patch for CVE-2015-4024

[5.3.3-45]

  • fix more functions accept paths with NUL character #1213407

[5.3.3-44]

  • soap: missing fix for #1222538 and #1204868

[5.3.3-43]

  • core: fix multipart/form-data request can use excessive amount of CPU usage CVE-2015-4024
  • fix various functions accept paths with NUL character CVE-2015-4026, #1213407
  • ftp: fix integer overflow leading to heap overflow when reading FTP file listing CVE-2015-4022
  • phar: fix buffer over-read in metadata parsing CVE-2015-2783
  • phar: invalid pointer free() in phar_tar_process_metadata() CVE-2015-3307
  • phar: fix buffer overflow in phar_set_inode() CVE-2015-3329
  • phar: fix memory corruption in phar_parse_tarfile caused by empty entry file name CVE-2015-4021
  • soap: more fix type confusion through unserialize #1222538

[5.3.3-42]

  • soap: more fix type confusion through unserialize #1204868

[5.3.3-41]

  • core: fix double in zend_ts_hash_graceful_destroy CVE-2014-9425
  • core: fix use-after-free in unserialize CVE-2015-2787
  • exif: fix free on unitialized pointer CVE-2015-0232
  • gd: fix buffer read overflow in gd_gif.c CVE-2014-9709
  • date: fix use after free vulnerability in unserialize CVE-2015-0273
  • enchant: fix heap buffer overflow in enchant_broker_request_dict CVE-2014-9705
  • phar: use after free in phar_object.c CVE-2015-2301
  • soap: fix type confusion through unserialize

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

php

5.3.3-46.el6_6

php-bcmath

5.3.3-46.el6_6

php-cli

5.3.3-46.el6_6

php-common

5.3.3-46.el6_6

php-dba

5.3.3-46.el6_6

php-devel

5.3.3-46.el6_6

php-embedded

5.3.3-46.el6_6

php-enchant

5.3.3-46.el6_6

php-fpm

5.3.3-46.el6_6

php-gd

5.3.3-46.el6_6

php-imap

5.3.3-46.el6_6

php-intl

5.3.3-46.el6_6

php-ldap

5.3.3-46.el6_6

php-mbstring

5.3.3-46.el6_6

php-mysql

5.3.3-46.el6_6

php-odbc

5.3.3-46.el6_6

php-pdo

5.3.3-46.el6_6

php-pgsql

5.3.3-46.el6_6

php-process

5.3.3-46.el6_6

php-pspell

5.3.3-46.el6_6

php-recode

5.3.3-46.el6_6

php-snmp

5.3.3-46.el6_6

php-soap

5.3.3-46.el6_6

php-tidy

5.3.3-46.el6_6

php-xml

5.3.3-46.el6_6

php-xmlrpc

5.3.3-46.el6_6

php-zts

5.3.3-46.el6_6

Oracle Linux i686

php

5.3.3-46.el6_6

php-bcmath

5.3.3-46.el6_6

php-cli

5.3.3-46.el6_6

php-common

5.3.3-46.el6_6

php-dba

5.3.3-46.el6_6

php-devel

5.3.3-46.el6_6

php-embedded

5.3.3-46.el6_6

php-enchant

5.3.3-46.el6_6

php-fpm

5.3.3-46.el6_6

php-gd

5.3.3-46.el6_6

php-imap

5.3.3-46.el6_6

php-intl

5.3.3-46.el6_6

php-ldap

5.3.3-46.el6_6

php-mbstring

5.3.3-46.el6_6

php-mysql

5.3.3-46.el6_6

php-odbc

5.3.3-46.el6_6

php-pdo

5.3.3-46.el6_6

php-pgsql

5.3.3-46.el6_6

php-process

5.3.3-46.el6_6

php-pspell

5.3.3-46.el6_6

php-recode

5.3.3-46.el6_6

php-snmp

5.3.3-46.el6_6

php-soap

5.3.3-46.el6_6

php-tidy

5.3.3-46.el6_6

php-xml

5.3.3-46.el6_6

php-xmlrpc

5.3.3-46.el6_6

php-zts

5.3.3-46.el6_6

Связанные уязвимости

oracle-oval
почти 10 лет назад

ELSA-2015-1135: php security and bug fix update (IMPORTANT)

suse-cvrf
почти 9 лет назад

Security update for php53

oracle-oval
больше 9 лет назад

ELSA-2015-1186: php55-php security update (IMPORTANT)

suse-cvrf
почти 10 лет назад

Security update for php5

suse-cvrf
почти 10 лет назад

Security update for php5

Уязвимость ELSA-2015-1218