MGASA-2015-0276
Dashboard / Vulnerabilities / MGASA-2015-0276
Summary: Updated php package fixes security vulnerabilities
Details: Segfault in Phar::convertToData on invalid file (CVE-2015-5589). Buffer overflow and stack smashing error in phar_fix_filepath (CVE-2015-5590). The php package has been updated to version 5.5.27, which fixes these issues, as well as other possible bugs and security issues, including the BACKRONYM flaw, which allows php-mysqlnd client connections that were supposed to use SSL/TLS to be downgraded to not use it.
References: https://advisories.mageia.org/MGASA-2015-0276.html, https://bugs.mageia.org/show_bug.cgi?id=16349, http://php.net/ChangeLog-5.php#5.5.27, http://openwall.com/lists/oss-security/2015/07/18/1
Affected packages
Package
Name: php
Purl: pkg:rpm/mageia/php?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
