Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian Wheezy DSA-3117-1 Critical PHP5 Out-Of-Bounds Issue

debian
Calendar Grey December 31, 2014
Debian Logo
Critical PHP5 patch released to resolve security issues in the Debian Wheezy environment. Immediate upgrade is advised.
Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development

Summary

As announced in DSA 3064-1 it has been decided to follow the stable
5.4.x releases for the Wheezy php5 packages. Consequently the
vulnerabilities are addressed by upgrading PHP to a new upstream version
5.4.36, which includes additional bug fixes, new features and possibly
incompatible changes. Please refer to the upstream changelog for more
information:

https://www.php.net/ChangeLog-5.php

Two additional patches were applied on top of the imported new upstream
version. An out-of-bounds read flaw was fixed which could lead php5-cgi
to crash. Moreover a bug with php5-pgsql in combination with PostgreSQL
9.1 was fixed (Debian Bug #773182).

For the stable distribution (wheezy), these problems have been fixed in
version 5.4.36-0+deb7u1.

We recommend that you upgrade your php5 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: php5
CVE ID: CVE-2014-8142

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here