Описание
Security update for php5
php5 was updated to fix two security issues.
These security issues were fixed:
- CVE-2014-9652: Out of bounds read in mconvert() (bnc#917150).
- CVE-2015-0273: Use after free vulnerability in unserialize() with DateTimeZone (bnc#918768).
Список пакетов
SUSE Linux Enterprise Module for Web and Scripting 12
SUSE Linux Enterprise Software Development Kit 12
Ссылки
- Link for SUSE-SU-2015:0424-1
- E-Mail link for SUSE-SU-2015:0424-1
- SUSE Security Ratings
- SUSE Bug 917150
- SUSE Bug 918768
- SUSE CVE CVE-2014-9652 page
- SUSE CVE CVE-2015-0273 page
Описание
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.
Затронутые продукты
Ссылки
- CVE-2014-9652
- SUSE Bug 917150
- SUSE Bug 917302
- SUSE Bug 918768
- SUSE Bug 980366
Описание
Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php_date_timezone_initialize_from_hash function or (b) DateTime data handled by the php_date_initialize_from_hash function.
Затронутые продукты
Ссылки
- CVE-2015-0273
- SUSE Bug 917302
- SUSE Bug 918768
- SUSE Bug 980366