MGASA-2013-0176
Dashboard / Vulnerabilities / MGASA-2013-0176
Summary: Updated php package fixes several issues
Details: Fixed php bug #64879 (Heap based buffer overflow in quoted_printable_encode, CVE-2013-2110). Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function. (CVE-2013-4635) See the changelog for additional bug fixes.
References: https://advisories.mageia.org/MGASA-2013-0176.html, https://bugs.mageia.org/show_bug.cgi?id=10492, https://bugs.php.net/bug.php?id=64879, http://www.php.net/ChangeLog-5.php, http://lwn.net/Vulnerabilities/559055
Affected packages
Package
Name: php
Purl: pkg:rpm/mageia/php?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
