OPENSUSE-SU-2019:1573-1
Vulnerability Summary
Timeline
Description
Security update for php7 This update for php7 fixes the following issues: Security issues fixed: - CVE-2019-9637: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128892). - CVE-2019-9675: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128886). - CVE-2019-9638: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension ((bsc#1128889). - CVE-2019-9639: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128887). - CVE-2019-9640: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128883). - CVE-2019-9022: Fixed a vulnerability which could allow a hostile DNS server to make PHP misuse memcpy (bsc#1126827). - CVE-2019-9024: Fixed a vulnerability in xmlrpc_decode function which could allow to a hostile XMLRPC server to cause memory read outside the allocated areas (bsc#1126821). - CVE-2019-9020: Fixed a heap out of bounds in xmlrpc_decode function (bsc#1126711). - CVE-2018-20783: Fixed a buffer over-read in PHAR reading functions which could allow an attacker to read allocated and unallocated memory when parsing a phar file (bsc#1127122). - CVE-2019-9021: Fixed a heap buffer-based buffer over-read in PHAR reading functions which could allow an attacker to read allocated and unallocated memory when parsing a phar file (bsc#1126713). - CVE-2019-9023: Fixed multiple heap-based buffer over-read instances in mbstring regular expression functions (bsc#1126823). - CVE-2019-9641: Fixed multiple invalid memory access in EXIF extension and improved insecure implementation of rename function (bsc#1128722). - CVE-2018-19935: Fixed a Denial of Service in php_imap.c which could be triggered via an empty string in the message argument to imap_mail (bsc#1118832). - CVE-2019-11034: Fixed a heap-buffer overflow in php_ifd_get32si() (bsc#1132838). - CVE-2019-11035: Fixed a heap-buffer overflow in exif_iif_add_value() (bsc#1132837). - CVE-2019-11036: Fixed buffer over-read in exif_process_IFD_TAG function leading to information disclosure (bsc#1134322). Other issue addressed: - Deleted README.default_socket_timeout which is not needed anymore (bsc#1129032). - Enabled php7 testsuite (bsc#1119396). This update was imported from the SUSE:SLE-15:Update update project.
Affected Systems
- opensuse•php7&distro=openSUSE Leap 15.0
< 7.2.5-lp150.2.19.1
References (35)
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BZGSTORTRYTIVYMVFOFYRIJIMKYXZ32T/#BZGSTORTRYTIVYMVFOFYRIJIMKYXZ32T
- https://bugzilla.suse.com/1118832
- https://bugzilla.suse.com/1119396
- https://bugzilla.suse.com/1126711
- https://bugzilla.suse.com/1126713
- https://bugzilla.suse.com/1126821
- https://bugzilla.suse.com/1126823
- https://bugzilla.suse.com/1126827
- https://bugzilla.suse.com/1127122
- https://bugzilla.suse.com/1128722
- https://bugzilla.suse.com/1128883
- https://bugzilla.suse.com/1128886
- https://bugzilla.suse.com/1128887
- https://bugzilla.suse.com/1128889
- https://bugzilla.suse.com/1128892
- https://bugzilla.suse.com/1129032
- https://bugzilla.suse.com/1132837
- https://bugzilla.suse.com/1132838
- https://bugzilla.suse.com/1134322
- https://www.suse.com/security/cve/CVE-2018-19935
- https://www.suse.com/security/cve/CVE-2018-20783
- https://www.suse.com/security/cve/CVE-2019-11034
- https://www.suse.com/security/cve/CVE-2019-11035
- https://www.suse.com/security/cve/CVE-2019-11036
- https://www.suse.com/security/cve/CVE-2019-9020
- https://www.suse.com/security/cve/CVE-2019-9021
- https://www.suse.com/security/cve/CVE-2019-9022
- https://www.suse.com/security/cve/CVE-2019-9023
- https://www.suse.com/security/cve/CVE-2019-9024
- https://www.suse.com/security/cve/CVE-2019-9637
- https://www.suse.com/security/cve/CVE-2019-9638
- https://www.suse.com/security/cve/CVE-2019-9639
- https://www.suse.com/security/cve/CVE-2019-9640
- https://www.suse.com/security/cve/CVE-2019-9641
- https://www.suse.com/security/cve/CVE-2019-9675