Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-3287

Опубликовано: 31 окт. 2019
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2019-3287: php security update (CRITICAL)

[5.3.3-50]

  • fix underflow in env_path_info in fpm_main.c CVE-2019-11043

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

php

5.3.3-50.el6_10

php-bcmath

5.3.3-50.el6_10

php-cli

5.3.3-50.el6_10

php-common

5.3.3-50.el6_10

php-dba

5.3.3-50.el6_10

php-devel

5.3.3-50.el6_10

php-embedded

5.3.3-50.el6_10

php-enchant

5.3.3-50.el6_10

php-fpm

5.3.3-50.el6_10

php-gd

5.3.3-50.el6_10

php-imap

5.3.3-50.el6_10

php-intl

5.3.3-50.el6_10

php-ldap

5.3.3-50.el6_10

php-mbstring

5.3.3-50.el6_10

php-mysql

5.3.3-50.el6_10

php-odbc

5.3.3-50.el6_10

php-pdo

5.3.3-50.el6_10

php-pgsql

5.3.3-50.el6_10

php-process

5.3.3-50.el6_10

php-pspell

5.3.3-50.el6_10

php-recode

5.3.3-50.el6_10

php-snmp

5.3.3-50.el6_10

php-soap

5.3.3-50.el6_10

php-tidy

5.3.3-50.el6_10

php-xml

5.3.3-50.el6_10

php-xmlrpc

5.3.3-50.el6_10

php-zts

5.3.3-50.el6_10

Oracle Linux i686

php

5.3.3-50.el6_10

php-bcmath

5.3.3-50.el6_10

php-cli

5.3.3-50.el6_10

php-common

5.3.3-50.el6_10

php-dba

5.3.3-50.el6_10

php-devel

5.3.3-50.el6_10

php-embedded

5.3.3-50.el6_10

php-enchant

5.3.3-50.el6_10

php-fpm

5.3.3-50.el6_10

php-gd

5.3.3-50.el6_10

php-imap

5.3.3-50.el6_10

php-intl

5.3.3-50.el6_10

php-ldap

5.3.3-50.el6_10

php-mbstring

5.3.3-50.el6_10

php-mysql

5.3.3-50.el6_10

php-odbc

5.3.3-50.el6_10

php-pdo

5.3.3-50.el6_10

php-pgsql

5.3.3-50.el6_10

php-process

5.3.3-50.el6_10

php-pspell

5.3.3-50.el6_10

php-recode

5.3.3-50.el6_10

php-snmp

5.3.3-50.el6_10

php-soap

5.3.3-50.el6_10

php-tidy

5.3.3-50.el6_10

php-xml

5.3.3-50.el6_10

php-xmlrpc

5.3.3-50.el6_10

php-zts

5.3.3-50.el6_10

Связанные CVE

Связанные уязвимости

CVSS3: 8.7
ubuntu
больше 5 лет назад

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVSS3: 8.1
redhat
больше 5 лет назад

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVSS3: 8.7
nvd
больше 5 лет назад

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVSS3: 8.7
debian
больше 5 лет назад

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below ...

suse-cvrf
больше 5 лет назад

Security update for php7