SUSE-SU-2016:2461-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2461-1
SUSE-SU-2016:2461-1
Summary: Security update for php53
Details: This update for php53 fixes the following issues: * CVE-2016-7411: php5: Memory corruption when destructing deserialized object * CVE-2016-7412: Heap overflow in mysqlnd when not receiving UNSIGNED_FLAG in BIT field * CVE-2016-7413: Use after free in wddx_deserialize * CVE-2016-7414: Out of bounds heap read when verifying signature of zip phar in phar_parse_zipfile * CVE-2016-7416: Stack based buffer overflow in msgfmt_format_message * CVE-2016-7417: Missing type check when unserializing SplArray * CVE-2016-7418: Null pointer dereference in php_wddx_push_element
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162461-1/, https://bugzilla.suse.com/999679, https://bugzilla.suse.com/999680, https://bugzilla.suse.com/999682, https://bugzilla.suse.com/999684, https://bugzilla.suse.com/999685, https://bugzilla.suse.com/999819, https://bugzilla.suse.com/999820, https://www.suse.com/security/cve/CVE-2016-7411, https://www.suse.com/security/cve/CVE-2016-7412, https://www.suse.com/security/cve/CVE-2016-7413, https://www.suse.com/security/cve/CVE-2016-7414, https://www.suse.com/security/cve/CVE-2016-7416, https://www.suse.com/security/cve/CVE-2016-7417, https://www.suse.com/security/cve/CVE-2016-7418
Affected packages
Package
Name: php53
Purl: pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS
Affected ranges
Type: ECOSYSTEM
Events:
