Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

openSUSE 13.2: 2015:1197-1 Important: php5 Type Confusion Fixes

opensuse
Calendar Grey July 6, 2015
Dist Opensuse Esm H88
A recent patch for php5 tackles various vulnerabilities, enhancing both the safety and reliability of openSUSE environments.
An update that fixes 12 vulnerabilities is now available.

Description

The PHP script interpreter was updated to receive various security fixes:

* CVE-2015-4602 [bnc#935224]: Fixed an incomplete Class unserialization

type confusion.

* CVE-2015-4599, CVE-2015-4600, CVE-2015-4601 [bnc#935226]: Fixed type

confusion issues in unserialize() with various SOAP methods.

* CVE-2015-4603 [bnc#935234]: Fixed exception::getTraceAsString type

confusion issue after unserialize.

* CVE-2015-4644 [bnc#935274]: Fixed a crash in php_pgsql_meta_data.

* CVE-2015-4643 [bnc#935275]: Fixed an integer overflow in ftp_genlist()

that could result in a heap overflow.

* CVE-2015-3411, CVE-2015-3412, CVE-2015-4598 [bnc#935227], [bnc#935232]:

Added missing null byte checks for paths in various PHP extensions.

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-471=1

- openSUSE 13.1:

zypper in -t patch openSUSE-2015-471=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

apache2-mod_php5-5.6.1-30.6

apache2-mod_php5-debuginfo-5.6.1-30.6

php5-5.6.1-30.6

php5-bcmath-5.6.1-30.6

php5-bcmath-debuginfo-5.6.1-30.6

php5-bz2-5.6.1-30.6

php5-bz2-debuginfo-5.6.1-30.6

php5-calendar-5.6.1-30.6

php5-calendar-debuginfo-5.6.1-30.6

php5-ctype-5.6.1-30.6

php5-ctype-debuginfo-5.6.1-30.6

php5-curl-5.6.1-30.6

php5-curl-debuginfo-5.6.1-30.6

php5-dba-5.6.1-30.6

php5-dba-debuginfo-5.6.1-30.6

php5-debuginfo-5.6.1-30.6

php5-debugsource-5.6.1-30.6

php5-devel-5.6.1-30.6

php5-dom-5.6.1-30.6

php5-dom-debuginfo-5.6.1-30.6

php5-enchant-5.6.1-30.6

php5-enchant-debuginfo-5.6.1-30.6

php5-exif-5.6.1-30.6

php5-exif-debuginfo-5.6.1-30.6

php5-fastcgi-5.6.1-30.6

php5-fastcgi-debuginfo-5.6.1-30.6

php5-fileinfo-5.6.1-30.6

php5-fileinfo-debuginfo-5.6.1-30.6

php5-firebird-5.6.1-30.6

php5-firebird-debuginfo-5.6.1-30.6

php5-fpm-5.6.1-30.6

php5-fpm-debuginfo-5.6.1-30.6

php5-ftp-5.6.1-30.6

php5-ftp-debuginfo-5.6.1-30.6

php5-gd-5.6.1-30.6

php5-gd-debuginfo-5.6.1-30.6

php5-gettext-5.6.1-30.6

php5-gettext-debu...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2015-3411.html

https://www.suse.com/security/cve/CVE-2015-3412.html

https://www.suse.com/security/cve/CVE-2015-4598.html

https://www.suse.com/security/cve/CVE-2015-4599.html

https://www.suse.com/security/cve/CVE-2015-4600.html

https://www.suse.com/security/cve/CVE-2015-4601.html

https://www.suse.com/security/cve/CVE-2015-4602.html

https://www.suse.com/security/cve/CVE-2015-4603.html

https://www.suse.com/security/cve/CVE-2015-4604.html

https://www.suse.com/security/cve/CVE-2015-4605.html

https://www.suse.com/security/cve/CVE-2015-4643.html

https://www.suse.com/security/cve/CVE-2015-4644.html

https://bugzilla.suse.com/935224

https://bugzilla.suse.com/935225

https://bugzilla.suse.com/935226

https://bugzilla.suse.com/935227

https://bugzilla.suse.com/935232

https://bugzilla.suse.com/935234

https://bugzilla.suse.com/935274

https://bugzilla.suse.com/935275

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:1197-1
Rating: important
Affected Products: openSUSE 13.2 openSUSE 13.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here