Описание
Security update for php7
This update for php7 fixes several issues.
These security issues were fixed:
- CVE-2017-12932: Prevent heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array size. Exploitation of this issue could have had an unspecified impact on the integrity of PHP (bsc#1054432).
- CVE-2017-12934: Prevent heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue could have had an unspecified impact on the integrity of PHP (bsc#1054408).
- CVE-2017-12933: The finish_nested_data function in ext/standard/var_unserializer.re was prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue could have had an unspecified impact on the integrity of PHP (bsc#1054430)
These non-security issues were fixed:
- bsc#1057104: php7-devel now requires php7-pear
- bsc#1057845: Fixed namespace encapsulation of imported classes/functions/constants
Список пакетов
SUSE Linux Enterprise Module for Web and Scripting 12
SUSE Linux Enterprise Software Development Kit 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP3
Ссылки
- Link for SUSE-SU-2017:2468-1
- E-Mail link for SUSE-SU-2017:2468-1
- SUSE Security Ratings
- SUSE Bug 1054408
- SUSE Bug 1054430
- SUSE Bug 1054432
- SUSE Bug 1057104
- SUSE Bug 1057845
- SUSE CVE CVE-2017-12932 page
- SUSE CVE CVE-2017-12933 page
- SUSE CVE CVE-2017-12934 page
Описание
ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array size. Exploitation of this issue can have an unspecified impact on the integrity of PHP.
Затронутые продукты
Ссылки
- CVE-2017-12932
- SUSE Bug 1054432
Описание
The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecified impact on the integrity of PHP.
Затронутые продукты
Ссылки
- CVE-2017-12933
- SUSE Bug 1054430
Описание
ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue can have an unspecified impact on the integrity of PHP.
Затронутые продукты
Ссылки
- CVE-2017-12934
- SUSE Bug 1054408