Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia: 2018-0390 Moderate: PHP Buffer Overflow and XSS Issues

mageia
Calendar Grey September 21, 2018
Dist Mageia Esm H88
Mageia enhances its php packages to mitigate security vulnerabilities, addressing XSS concerns and heap overflow risks in significantly impacted sectors.
- Int Overflow lead to Heap OverFlow in exif_thumbnail_extract of exif.c (CVE-2018-14883) - heap-buffer-overflow (READ of size 48) while reading exif data (CVE-2018-14851) - XS...

Summary

- Int Overflow lead to Heap OverFlow in exif_thumbnail_extract of exif.c (CVE-2018-14883) - heap-buffer-overflow (READ of size 48) while reading exif data (CVE-2018-14851) - XSS due to the header Transfer-Encoding: chunked

References

- https://bugs.mageia.org/show_bug.cgi?id=23564

- https://www.php.net/archive/2018.php

- https://www.php.net/ChangeLog-5.php

- https://www.cve.org/CVERecord?id=CVE-2018-14851

- https://www.cve.org/CVERecord?id=CVE-2018-14883

Resolution

SRPMS

- 6/core/php-5.6.38-1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 21 Sep 2018
URL: https://advisories.mageia.org/MGASA-2018-0390.html
Type: security
CVE: CVE-2018-14851, CVE-2018-14883

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here