Описание
Security update for php7
This update for php7 fixes the following issues:
The following security vulnerabilities were fixed:
-
CVE-2018-14851: Fixed an out-of-bound read in exif_process_IFD_in_MAKERNOTE, which could be exploited by an attacker via crafted JPG files, and could result in an application crash. (bsc#1103659)
-
CVE-2017-9120: Fixed an buffer overflow in mysqli_real_escape_string, which could be exploited via along string and could result in an application crash or have other unspecified impacts. (bsc#1103661)
Список пакетов
SUSE Linux Enterprise Module for Web and Scripting 15
Ссылки
- Link for SUSE-SU-2018:2337-1
- E-Mail link for SUSE-SU-2018:2337-1
- SUSE Security Ratings
- SUSE Bug 1103659
- SUSE Bug 1103661
- SUSE CVE CVE-2017-9120 page
- SUSE CVE CVE-2018-14851 page
Описание
PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string.
Затронутые продукты
Ссылки
- CVE-2017-9120
- SUSE Bug 1103661
Описание
exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file.
Затронутые продукты
Ссылки
- CVE-2018-14851
- SUSE Bug 1103659