SUSE-SU-2016:1504-1
Vulnerability Summary
Timeline
Description
Security update for php5 This update for php5 fixes the following issues: Security issues fixed: - CVE-2016-4346: heap overflow in ext/standard/string.c (bsc#977994) - CVE-2016-4342: heap corruption in tar/zip/phar parser (bsc#977991) - CVE-2016-4537, CVE-2016-4538: bcpowmod accepts negative scale causing heap buffer overflow corrupting _one_ definition (bsc#978827) - CVE-2016-4539: Malformed input causes segmentation fault in xml_parse_into_struct() function (bsc#978828) - CVE-2016-4540, CVE-2016-4541: Out-of-bounds memory read in zif_grapheme_stripos when given negative offset (bsc#978829) - CVE-2016-4542, CVE-2016-4543, CVE-2016-4544: Out-of-bounds heap memory read in exif_read_data() caused by malformed input (bsc#978830) - CVE-2015-4116: Use-after-free vulnerability in the spl_ptr_heap_insert function (bsc#980366) - CVE-2015-8873: Stack consumption vulnerability in Zend/zend_exceptions.c (bsc#980373) - CVE-2015-8874: Stack consumption vulnerability in GD (bsc#980375)
Affected Systems
- suse•php5&distro=SUSE Linux Enterprise Module for Web and Scripting 12
< 5.5.14-59.2
- suse•php5&distro=SUSE Linux Enterprise Software Development Kit 12
< 5.5.14-59.2
- suse•php5&distro=SUSE Linux Enterprise Software Development Kit 12 SP1
< 5.5.14-59.2
References (23)
- https://www.suse.com/support/update/announcement/2016/suse-su-20161504-1/
- https://bugzilla.suse.com/977991
- https://bugzilla.suse.com/977994
- https://bugzilla.suse.com/978827
- https://bugzilla.suse.com/978828
- https://bugzilla.suse.com/978829
- https://bugzilla.suse.com/978830
- https://bugzilla.suse.com/980366
- https://bugzilla.suse.com/980373
- https://bugzilla.suse.com/980375
- https://www.suse.com/security/cve/CVE-2015-4116
- https://www.suse.com/security/cve/CVE-2015-8873
- https://www.suse.com/security/cve/CVE-2015-8874
- https://www.suse.com/security/cve/CVE-2016-4342
- https://www.suse.com/security/cve/CVE-2016-4346
- https://www.suse.com/security/cve/CVE-2016-4537
- https://www.suse.com/security/cve/CVE-2016-4538
- https://www.suse.com/security/cve/CVE-2016-4539
- https://www.suse.com/security/cve/CVE-2016-4540
- https://www.suse.com/security/cve/CVE-2016-4541
- https://www.suse.com/security/cve/CVE-2016-4542
- https://www.suse.com/security/cve/CVE-2016-4543
- https://www.suse.com/security/cve/CVE-2016-4544