USN-3566-1
Dashboard / Vulnerabilities / USN-3566-1
USN-3566-1
Summary: php5 vulnerabilities
Details: It was discovered that PHP incorrectly handled the PHAR 404 error page. A remote attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks. (CVE-2018-5712) It was discovered that PHP incorrectly handled memory when unserializing certain data. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2017-12933) It was discovered that PHP incorrectly handled 'front of' and 'back of' date directives. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2017-16642)
References: https://ubuntu.com/security/notices/USN-3566-1, https://ubuntu.com/security/CVE-2017-12933, https://ubuntu.com/security/CVE-2017-16642, https://ubuntu.com/security/CVE-2018-5712
Affected packages
Package
Name: php5
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu4.23?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
