Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:1294-1

Опубликовано: 15 мая 2018
Источник: suse-cvrf

Описание

Security update for php53

This update for php53 fixes the following issues:

Security issues fixed:

  • CVE-2018-10545: Fix access controls in FPM child processes (bsc#1091367).
  • CVE-2018-10547: Fix Reflected XSS on the PHAR 403 and 404 error pages (bsc#1091362).
  • CVE-2018-10546: Fix an infinite loop exists in ext/iconv/iconv.c (bsc#1091363).
  • CVE-2018-10548: Fix remote denial of service in ext/ldap/ldap.c (bsc#1091355).

Список пакетов

SUSE Linux Enterprise Point of Sale 11 SP3
apache2-mod_php53-5.3.17-112.23.1
php53-5.3.17-112.23.1
php53-bcmath-5.3.17-112.23.1
php53-bz2-5.3.17-112.23.1
php53-calendar-5.3.17-112.23.1
php53-ctype-5.3.17-112.23.1
php53-curl-5.3.17-112.23.1
php53-dba-5.3.17-112.23.1
php53-dom-5.3.17-112.23.1
php53-exif-5.3.17-112.23.1
php53-fastcgi-5.3.17-112.23.1
php53-fileinfo-5.3.17-112.23.1
php53-ftp-5.3.17-112.23.1
php53-gd-5.3.17-112.23.1
php53-gettext-5.3.17-112.23.1
php53-gmp-5.3.17-112.23.1
php53-iconv-5.3.17-112.23.1
php53-intl-5.3.17-112.23.1
php53-json-5.3.17-112.23.1
php53-ldap-5.3.17-112.23.1
php53-mbstring-5.3.17-112.23.1
php53-mcrypt-5.3.17-112.23.1
php53-mysql-5.3.17-112.23.1
php53-odbc-5.3.17-112.23.1
php53-openssl-5.3.17-112.23.1
php53-pcntl-5.3.17-112.23.1
php53-pdo-5.3.17-112.23.1
php53-pear-5.3.17-112.23.1
php53-pgsql-5.3.17-112.23.1
php53-pspell-5.3.17-112.23.1
php53-shmop-5.3.17-112.23.1
php53-snmp-5.3.17-112.23.1
php53-soap-5.3.17-112.23.1
php53-suhosin-5.3.17-112.23.1
php53-sysvmsg-5.3.17-112.23.1
php53-sysvsem-5.3.17-112.23.1
php53-sysvshm-5.3.17-112.23.1
php53-tokenizer-5.3.17-112.23.1
php53-wddx-5.3.17-112.23.1
php53-xmlreader-5.3.17-112.23.1
php53-xmlrpc-5.3.17-112.23.1
php53-xmlwriter-5.3.17-112.23.1
php53-xsl-5.3.17-112.23.1
php53-zip-5.3.17-112.23.1
php53-zlib-5.3.17-112.23.1
SUSE Linux Enterprise Server 11 SP3-LTSS
apache2-mod_php53-5.3.17-112.23.1
php53-5.3.17-112.23.1
php53-bcmath-5.3.17-112.23.1
php53-bz2-5.3.17-112.23.1
php53-calendar-5.3.17-112.23.1
php53-ctype-5.3.17-112.23.1
php53-curl-5.3.17-112.23.1
php53-dba-5.3.17-112.23.1
php53-dom-5.3.17-112.23.1
php53-exif-5.3.17-112.23.1
php53-fastcgi-5.3.17-112.23.1
php53-fileinfo-5.3.17-112.23.1
php53-ftp-5.3.17-112.23.1
php53-gd-5.3.17-112.23.1
php53-gettext-5.3.17-112.23.1
php53-gmp-5.3.17-112.23.1
php53-iconv-5.3.17-112.23.1
php53-intl-5.3.17-112.23.1
php53-json-5.3.17-112.23.1
php53-ldap-5.3.17-112.23.1
php53-mbstring-5.3.17-112.23.1
php53-mcrypt-5.3.17-112.23.1
php53-mysql-5.3.17-112.23.1
php53-odbc-5.3.17-112.23.1
php53-openssl-5.3.17-112.23.1
php53-pcntl-5.3.17-112.23.1
php53-pdo-5.3.17-112.23.1
php53-pear-5.3.17-112.23.1
php53-pgsql-5.3.17-112.23.1
php53-pspell-5.3.17-112.23.1
php53-shmop-5.3.17-112.23.1
php53-snmp-5.3.17-112.23.1
php53-soap-5.3.17-112.23.1
php53-suhosin-5.3.17-112.23.1
php53-sysvmsg-5.3.17-112.23.1
php53-sysvsem-5.3.17-112.23.1
php53-sysvshm-5.3.17-112.23.1
php53-tokenizer-5.3.17-112.23.1
php53-wddx-5.3.17-112.23.1
php53-xmlreader-5.3.17-112.23.1
php53-xmlrpc-5.3.17-112.23.1
php53-xmlwriter-5.3.17-112.23.1
php53-xsl-5.3.17-112.23.1
php53-zip-5.3.17-112.23.1
php53-zlib-5.3.17-112.23.1
SUSE Linux Enterprise Server 11 SP3-TERADATA
apache2-mod_php53-5.3.17-112.23.1
php53-5.3.17-112.23.1
php53-bcmath-5.3.17-112.23.1
php53-bz2-5.3.17-112.23.1
php53-calendar-5.3.17-112.23.1
php53-ctype-5.3.17-112.23.1
php53-curl-5.3.17-112.23.1
php53-dba-5.3.17-112.23.1
php53-dom-5.3.17-112.23.1
php53-exif-5.3.17-112.23.1
php53-fastcgi-5.3.17-112.23.1
php53-fileinfo-5.3.17-112.23.1
php53-ftp-5.3.17-112.23.1
php53-gd-5.3.17-112.23.1
php53-gettext-5.3.17-112.23.1
php53-gmp-5.3.17-112.23.1
php53-iconv-5.3.17-112.23.1
php53-intl-5.3.17-112.23.1
php53-json-5.3.17-112.23.1
php53-ldap-5.3.17-112.23.1
php53-mbstring-5.3.17-112.23.1
php53-mcrypt-5.3.17-112.23.1
php53-mysql-5.3.17-112.23.1
php53-odbc-5.3.17-112.23.1
php53-openssl-5.3.17-112.23.1
php53-pcntl-5.3.17-112.23.1
php53-pdo-5.3.17-112.23.1
php53-pear-5.3.17-112.23.1
php53-pgsql-5.3.17-112.23.1
php53-pspell-5.3.17-112.23.1
php53-shmop-5.3.17-112.23.1
php53-snmp-5.3.17-112.23.1
php53-soap-5.3.17-112.23.1
php53-suhosin-5.3.17-112.23.1
php53-sysvmsg-5.3.17-112.23.1
php53-sysvsem-5.3.17-112.23.1
php53-sysvshm-5.3.17-112.23.1
php53-tokenizer-5.3.17-112.23.1
php53-wddx-5.3.17-112.23.1
php53-xmlreader-5.3.17-112.23.1
php53-xmlrpc-5.3.17-112.23.1
php53-xmlwriter-5.3.17-112.23.1
php53-xsl-5.3.17-112.23.1
php53-zip-5.3.17-112.23.1
php53-zlib-5.3.17-112.23.1
SUSE Linux Enterprise Server 11 SP4
apache2-mod_php53-5.3.17-112.23.1
php53-5.3.17-112.23.1
php53-bcmath-5.3.17-112.23.1
php53-bz2-5.3.17-112.23.1
php53-calendar-5.3.17-112.23.1
php53-ctype-5.3.17-112.23.1
php53-curl-5.3.17-112.23.1
php53-dba-5.3.17-112.23.1
php53-dom-5.3.17-112.23.1
php53-exif-5.3.17-112.23.1
php53-fastcgi-5.3.17-112.23.1
php53-fileinfo-5.3.17-112.23.1
php53-ftp-5.3.17-112.23.1
php53-gd-5.3.17-112.23.1
php53-gettext-5.3.17-112.23.1
php53-gmp-5.3.17-112.23.1
php53-iconv-5.3.17-112.23.1
php53-intl-5.3.17-112.23.1
php53-json-5.3.17-112.23.1
php53-ldap-5.3.17-112.23.1
php53-mbstring-5.3.17-112.23.1
php53-mcrypt-5.3.17-112.23.1
php53-mysql-5.3.17-112.23.1
php53-odbc-5.3.17-112.23.1
php53-openssl-5.3.17-112.23.1
php53-pcntl-5.3.17-112.23.1
php53-pdo-5.3.17-112.23.1
php53-pear-5.3.17-112.23.1
php53-pgsql-5.3.17-112.23.1
php53-pspell-5.3.17-112.23.1
php53-shmop-5.3.17-112.23.1
php53-snmp-5.3.17-112.23.1
php53-soap-5.3.17-112.23.1
php53-suhosin-5.3.17-112.23.1
php53-sysvmsg-5.3.17-112.23.1
php53-sysvsem-5.3.17-112.23.1
php53-sysvshm-5.3.17-112.23.1
php53-tokenizer-5.3.17-112.23.1
php53-wddx-5.3.17-112.23.1
php53-xmlreader-5.3.17-112.23.1
php53-xmlrpc-5.3.17-112.23.1
php53-xmlwriter-5.3.17-112.23.1
php53-xsl-5.3.17-112.23.1
php53-zip-5.3.17-112.23.1
php53-zlib-5.3.17-112.23.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
apache2-mod_php53-5.3.17-112.23.1
php53-5.3.17-112.23.1
php53-bcmath-5.3.17-112.23.1
php53-bz2-5.3.17-112.23.1
php53-calendar-5.3.17-112.23.1
php53-ctype-5.3.17-112.23.1
php53-curl-5.3.17-112.23.1
php53-dba-5.3.17-112.23.1
php53-dom-5.3.17-112.23.1
php53-exif-5.3.17-112.23.1
php53-fastcgi-5.3.17-112.23.1
php53-fileinfo-5.3.17-112.23.1
php53-ftp-5.3.17-112.23.1
php53-gd-5.3.17-112.23.1
php53-gettext-5.3.17-112.23.1
php53-gmp-5.3.17-112.23.1
php53-iconv-5.3.17-112.23.1
php53-intl-5.3.17-112.23.1
php53-json-5.3.17-112.23.1
php53-ldap-5.3.17-112.23.1
php53-mbstring-5.3.17-112.23.1
php53-mcrypt-5.3.17-112.23.1
php53-mysql-5.3.17-112.23.1
php53-odbc-5.3.17-112.23.1
php53-openssl-5.3.17-112.23.1
php53-pcntl-5.3.17-112.23.1
php53-pdo-5.3.17-112.23.1
php53-pear-5.3.17-112.23.1
php53-pgsql-5.3.17-112.23.1
php53-pspell-5.3.17-112.23.1
php53-shmop-5.3.17-112.23.1
php53-snmp-5.3.17-112.23.1
php53-soap-5.3.17-112.23.1
php53-suhosin-5.3.17-112.23.1
php53-sysvmsg-5.3.17-112.23.1
php53-sysvsem-5.3.17-112.23.1
php53-sysvshm-5.3.17-112.23.1
php53-tokenizer-5.3.17-112.23.1
php53-wddx-5.3.17-112.23.1
php53-xmlreader-5.3.17-112.23.1
php53-xmlrpc-5.3.17-112.23.1
php53-xmlwriter-5.3.17-112.23.1
php53-xsl-5.3.17-112.23.1
php53-zip-5.3.17-112.23.1
php53-zlib-5.3.17-112.23.1
SUSE Linux Enterprise Software Development Kit 11 SP4
php53-devel-5.3.17-112.23.1
php53-imap-5.3.17-112.23.1
php53-posix-5.3.17-112.23.1
php53-readline-5.3.17-112.23.1
php53-sockets-5.3.17-112.23.1
php53-sqlite-5.3.17-112.23.1
php53-tidy-5.3.17-112.23.1

Описание

An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second user's PHP applications by running gcore on the PID of the PHP-FPM worker process.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:apache2-mod_php53-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-bcmath-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-bz2-5.3.17-112.23.1

Ссылки

Описание

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:apache2-mod_php53-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-bcmath-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-bz2-5.3.17-112.23.1

Ссылки

Описание

An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-5712.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:apache2-mod_php53-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-bcmath-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-bz2-5.3.17-112.23.1

Ссылки

Описание

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer dereference and application crash) because of mishandling of the ldap_get_dn return value.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:apache2-mod_php53-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-bcmath-5.3.17-112.23.1
SUSE Linux Enterprise Point of Sale 11 SP3:php53-bz2-5.3.17-112.23.1

Ссылки
Уязвимость SUSE-SU-2018:1294-1