SUSE-SU-2018:0308-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0308-1
SUSE-SU-2018:0308-1
Summary: Security update for php7
Details: This update for php7 fixes several issues. These security issues were fixed: - CVE-2018-5712: Prevent reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file that allowed for information disclosure (bsc#1076220). - CVE-2018-5711: Prevent integer signedness error that could have lead to an infinite loop via a crafted GIF file allowing for DoS (bsc#1076391)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180308-1/, https://bugzilla.suse.com/1076220, https://bugzilla.suse.com/1076391, https://www.suse.com/security/cve/CVE-2018-5711, https://www.suse.com/security/cve/CVE-2018-5712
Affected packages
Package
Name: php7
Purl: pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012
Affected ranges
Type: ECOSYSTEM
Events:
