MGASA-2015-0258
Dashboard / Vulnerabilities / MGASA-2015-0258
MGASA-2015-0258
Summary: Updated php package fixes security vulnerability
Details: Incorrect handling of paths with NULs (CVE-2015-4598). OS command injection vulnerability in escapeshellarg (CVE-2015-4642). Integer overflow in ftp_genlist() resulting in heap overflow (CVE-2015-4643). Segfault in php_pgsql_meta_data (CVE-2015-4644). PHP has been updated to version 5.5.26, which fixes multiple bugs and potential security issues. Please see the upstream ChangeLog for details.
References: https://advisories.mageia.org/MGASA-2015-0258.html, https://bugs.mageia.org/show_bug.cgi?id=16115, http://php.net/ChangeLog-5.php#5.5.26, http://openwall.com/lists/oss-security/2015/06/16/12, http://openwall.com/lists/oss-security/2015/06/18/6
Affected packages
Package
Name: php
Purl: pkg:rpm/mageia/php?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
