SUSE-SU-2016:2459-1

Advisory lineage Upstream: 16 Downstream: 0
Published: 05 Oct 2016, 12:41
Last modified:04 Feb 2026, 03:44

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Oct 2016, 12:41
Published
Vulnerability first disclosed
04 Feb 2026, 03:44
Last Modified
Vulnerability information updated

Description

Security update for php53 This update for php53 fixes the following security issues: * CVE-2016-7124: Create an Unexpected Object and Don't Invoke __wakeup() in Deserialization * CVE-2016-7125: PHP Session Data Injection Vulnerability * CVE-2016-7126: select_colors write out-of-bounds * CVE-2016-7127: imagegammacorrect allowed arbitrary write access * CVE-2016-7128: Memory Leakage In exif_process_IFD_in_TIFF * CVE-2016-7129: wddx_deserialize allows illegal memory access * CVE-2016-7130: wddx_deserialize null dereference * CVE-2016-7131: wddx_deserialize null dereference with invalid xml * CVE-2016-7132: wddx_deserialize null dereference in php_wddx_pop_element * CVE-2016-7411: php5: Memory corruption when destructing deserialized object * CVE-2016-7412: Heap overflow in mysqlnd when not receiving UNSIGNED_FLAG in BIT field * CVE-2016-7413: Use after free in wddx_deserialize * CVE-2016-7414: Out of bounds heap read when verifying signature of zip phar in phar_parse_zipfile * CVE-2016-7416: Stack based buffer overflow in msgfmt_format_message * CVE-2016-7417: Missing type check when unserializing SplArray * CVE-2016-7418: Null pointer dereference in php_wddx_push_element

Affected Systems

  • susephp53&distro=SUSE Linux Enterprise Point of Sale 11 SP3

    < 5.3.17-84.1

  • susephp53&distro=SUSE Linux Enterprise Server 11 SP3-LTSS

    < 5.3.17-84.1

  • susephp53&distro=SUSE Linux Enterprise Server 11 SP3-TERADATA

    < 5.3.17-84.1

  • susephp53&distro=SUSE Linux Enterprise Server 11 SP4

    < 5.3.17-84.1

  • susephp53&distro=SUSE Linux Enterprise Server for SAP Applications 11 SP4

    < 5.3.17-84.1

  • susephp53&distro=SUSE Linux Enterprise Software Development Kit 11 SP4

    < 5.3.17-84.1

  • susephp53&distro=SUSE Manager 2.1

    < 5.3.17-84.1

  • susephp53&distro=SUSE Manager Proxy 2.1

    < 5.3.17-84.1

  • susephp53&distro=SUSE OpenStack Cloud 5

    < 5.3.17-84.1

References (33)