Описание
Security update for php72
This update for php72 fixes the following issues:
Security issues fixed:
- CVE-2019-11034: Fixed a heap-buffer overflow in php_ifd_get32si() (bsc#1132838).
- CVE-2019-11035: Fixed a heap-buffer overflow in exif_iif_add_value() (bsc#1132837).
- CVE-2019-11036: Fixed buffer over-read in exif_process_IFD_TAG function leading to information disclosure (bsc#1134322).
Non-security issue fixed:
- Use system gd (bsc#1133714).
Список пакетов
SUSE Linux Enterprise Module for Web and Scripting 12
SUSE Linux Enterprise Software Development Kit 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP4
Ссылки
- Link for SUSE-SU-2019:1360-1
- E-Mail link for SUSE-SU-2019:1360-1
- SUSE Security Ratings
- SUSE Bug 1132837
- SUSE Bug 1132838
- SUSE Bug 1133714
- SUSE Bug 1134322
- SUSE CVE CVE-2019-11034 page
- SUSE CVE CVE-2019-11035 page
- SUSE CVE CVE-2019-11036 page
Описание
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
Затронутые продукты
Ссылки
- CVE-2019-11034
- SUSE Bug 1132838
Описание
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.
Затронутые продукты
Ссылки
- CVE-2019-11035
- SUSE Bug 1132837
Описание
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
Затронутые продукты
Ссылки
- CVE-2019-11036
- SUSE Bug 1134322