MGASA-2013-0379
Dashboard / Vulnerabilities / MGASA-2013-0379
Summary: Updated php packages fix multiple security vulnerabilities
Details: Updated php packages fix security vulnerabilities: Stefan Esser discovered that PHP incorrectly parsed certificates. An attacker could use a malformed certificate to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2013-6420). It was discovered that PHP incorrectly handled DateInterval objects. An attacker could use this issue to cause PHP to crash, resulting in a denial of service (CVE-2013-6712).
References: https://advisories.mageia.org/MGASA-2013-0379.html, http://www.php.net/ChangeLog-5.php#5.4.23, http://www.ubuntu.com/usn/usn-2055-1/, https://bugs.mageia.org/show_bug.cgi?id=11947
Affected packages
Package
Name: php
Purl: pkg:rpm/mageia/php?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
