SUSE-SU-2017:3237-1
Dashboard / Vulnerabilities / SUSE-SU-2017:3237-1
SUSE-SU-2017:3237-1
Summary: Security update for php7
Details: This update for php7 fixes the following issues: Security issues fixed: - CVE-2017-16642: Fix timelib_meridian error that could be used to leak information from the interpreter (bsc#1067441). - CVE-2017-9229: Fix invalid pointer dereference in left_adjust_char_head() (bsc#1069631). - CVE-2017-9228: Fix heap out-of-bounds write that occurs in bitset_set_range() during regex compilation (bsc#1069606). Bugs fixed: - Fix wrong reference when serialize/unserialize an object (bsc#1063815).
References: https://www.suse.com/support/update/announcement/2017/suse-su-20173237-1/, https://bugzilla.suse.com/1063815, https://bugzilla.suse.com/1067441, https://bugzilla.suse.com/1069606, https://bugzilla.suse.com/1069631, https://www.suse.com/security/cve/CVE-2017-16642, https://www.suse.com/security/cve/CVE-2017-9228, https://www.suse.com/security/cve/CVE-2017-9229
Affected packages
Package
Name: php7
Purl: pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012
Affected ranges
Type: ECOSYSTEM
Events:
