SUSE-SU-2016:1504-1
Dashboard / Vulnerabilities / SUSE-SU-2016:1504-1
SUSE-SU-2016:1504-1
Summary: Security update for php5
Details: This update for php5 fixes the following issues: Security issues fixed: - CVE-2016-4346: heap overflow in ext/standard/string.c (bsc#977994) - CVE-2016-4342: heap corruption in tar/zip/phar parser (bsc#977991) - CVE-2016-4537, CVE-2016-4538: bcpowmod accepts negative scale causing heap buffer overflow corrupting _one_ definition (bsc#978827) - CVE-2016-4539: Malformed input causes segmentation fault in xml_parse_into_struct() function (bsc#978828) - CVE-2016-4540, CVE-2016-4541: Out-of-bounds memory read in zif_grapheme_stripos when given negative offset (bsc#978829) - CVE-2016-4542, CVE-2016-4543, CVE-2016-4544: Out-of-bounds heap memory read in exif_read_data() caused by malformed input (bsc#978830) - CVE-2015-4116: Use-after-free vulnerability in the spl_ptr_heap_insert function (bsc#980366) - CVE-2015-8873: Stack consumption vulnerability in Zend/zend_exceptions.c (bsc#980373) - CVE-2015-8874: Stack consumption vulnerability in GD (bsc#980375)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20161504-1/, https://bugzilla.suse.com/977991, https://bugzilla.suse.com/977994, https://bugzilla.suse.com/978827, https://bugzilla.suse.com/978828, https://bugzilla.suse.com/978829, https://bugzilla.suse.com/978830, https://bugzilla.suse.com/980366, https://bugzilla.suse.com/980373, https://bugzilla.suse.com/980375, https://www.suse.com/security/cve/CVE-2015-4116, https://www.suse.com/security/cve/CVE-2015-8873, https://www.suse.com/security/cve/CVE-2015-8874, https://www.suse.com/security/cve/CVE-2016-4342, https://www.suse.com/security/cve/CVE-2016-4346, https://www.suse.com/security/cve/CVE-2016-4537, https://www.suse.com/security/cve/CVE-2016-4538, https://www.suse.com/security/cve/CVE-2016-4539, https://www.suse.com/security/cve/CVE-2016-4540, https://www.suse.com/security/cve/CVE-2016-4541, https://www.suse.com/security/cve/CVE-2016-4542, https://www.suse.com/security/cve/CVE-2016-4543, https://www.suse.com/security/cve/CVE-2016-4544
Affected packages
Package
Name: php5
Purl: pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012
Affected ranges
Type: ECOSYSTEM
Events:
