MGASA-2016-0267

Advisory lineage Upstream: 8 Downstream: 0
Published: 26 Jul 2016, 21:59
Last modified:16 Apr 2026, 06:22

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Jul 2016, 21:59
Published
Vulnerability first disclosed
16 Apr 2026, 06:22
Last Modified
Vulnerability information updated

Description

Updated php/xmlrpc-epi/timezone packages fix security vulnerability Stack-based buffer overflow vulnerability in virtual_file_ex() (CVE-2016-6289). Use After Free in unserialize() with Unexpected Session Deserialization (CVE-2016-6290). Out of bound read in exif_process_IFD_in_MAKERNOTE() (CVE-2016-6291). NULL Pointer Dereference in exif_process_user_comment() (CVE-2016-6292). locale_accept_from_http() out-of-bounds access (CVE-2016-6294). Use After Free Vulnerability in SNMP with GC and unserialize() (CVE-2016-6295). heap-buffer-overflow (write) simplestring_addn() simplestring.c in php-xmlrpc (CVE-2016-6296). Stack-based buffer overflow vulnerability in php_stream_zip_opener() (CVE-2016-6297). The php package has been updated to version 5.6.24, fixing these issues and several other bugs. See the upstream ChangeLog for details. The CVE-2016-6296 issue was in the xmlrpc-epi library, which has been patched. Additionally, the timezone and php-timezonedb packages have been updated with the latest timezone data.

Affected Systems

  • mageiaphp

    < 5.6.24-1.mga5

  • mageiaphp-timezonedb

    < 2016.6-1.mga5

  • mageiatimezone

    < 2016f-1.mga5

  • mageiaxmlrpc-epi

    < 0.54.2-5.1.mga5

References (8)