SUSE-SU-2015:1818-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1818-1
SUSE-SU-2015:1818-1
Summary: Security update for php53
Details: This update of PHP5 brings several security fixes. Security fixes: * CVE-2015-6831: A use after free vulnerability in unserialize() has been fixed which could be used to crash php or potentially execute code. [bnc#942291] [bnc#942294] [bnc#942295] * CVE-2015-6836: A SOAP serialize_function_call() type confusion leading to remote code execution problem was fixed. [bnc#945428] * CVE-2015-6837 CVE-2015-6838: Two NULL pointer dereferences in the XSLTProcessor class were fixed. [bnc#945412] It also includes a bugfix for the odbc module: * compare with SQL_NULL_DATA correctly [bnc#935074]
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151818-1/, https://bugzilla.suse.com/935074, https://bugzilla.suse.com/942291, https://bugzilla.suse.com/942294, https://bugzilla.suse.com/942295, https://bugzilla.suse.com/942296, https://bugzilla.suse.com/945412, https://bugzilla.suse.com/945428, https://www.suse.com/security/cve/CVE-2015-6831, https://www.suse.com/security/cve/CVE-2015-6833, https://www.suse.com/security/cve/CVE-2015-6836, https://www.suse.com/security/cve/CVE-2015-6837, https://www.suse.com/security/cve/CVE-2015-6838
Affected packages
Package
Name: php53
Purl: pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
