MGASA-2016-0213
Dashboard / Vulnerabilities / MGASA-2016-0213
MGASA-2016-0213
Summary: Updated php packages fix security vulnerabilities
Details: Updated php packages fix security vulnerabilities: In php-intl, get_icu_value_internal out-of-bounds read (CVE-2016-5093). Integer Overflow in php_html_entities (CVE-2016-5094). Integer underflow / arbitrary null write in fread/gzread (CVE-2016-5096). The php package has been updated to version 5.6.22, which fixes these security issues and other bugs. See the upstream ChangeLog for more details.
References: https://advisories.mageia.org/MGASA-2016-0213.html, https://bugs.mageia.org/show_bug.cgi?id=18545, http://www.php.net/ChangeLog-5.php#5.6.22
Affected packages
Package
Name: php
Purl: pkg:rpm/mageia/php?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
