MGASA-2013-0172
Dashboard / Vulnerabilities / MGASA-2013-0172
Summary: Updated php packages fix security vulnerabilies
Details: Heap based buffer overflow in quoted_printable_encode() in PHP before version 5.4.16 (CVE-2013-2110). Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function. (CVE-2013-4635) This update provides PHP version 5.4.16 which fixes this as well as several other issues.
References: https://advisories.mageia.org/MGASA-2013-0172.html, https://bugs.mageia.org/show_bug.cgi?id=10456, http://www.php.net/ChangeLog-5.php, http://lwn.net/Vulnerabilities/559055/
Affected packages
Package
Name: php
Purl: pkg:rpm/mageia/php?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
