Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

openSUSE Leap 42.1: 2016:1373-1 Important PHP5 Security Update

opensuse
Calendar Grey May 20, 2016
Scroller Opensuse
Important announcement for openSUSE addressing several vulnerabilities in php5 that could lead to denial of service and unauthorized code execution.
An update that fixes 5 vulnerabilities is now available

Description

This update for php5 fixes the following security issues:

- CVE-2016-4073: A remote attacker could have caused denial of service, or

possibly execute arbitrary code, due to incorrect handling of string

length calculations in mb_strcut() (bsc#977003)

- CVE-2015-8867: The PHP function openssl_random_pseudo_bytes() did not

return cryptographically secure random bytes (bsc#977005)

- CVE-2016-4070: The libxml_disable_entity_loader() setting was shared

between threads, which could have resulted in XML external entity

injection and entity expansion issues (bsc#976997)

- CVE-2015-8866: A remote attacker could have caused denial of service due

to incorrect handling of large strings in php_raw_url_encode()

(bsc#976996)

- CVE-2016-4071: A remote attacker could have caused denial of service, or

possibly execute arbitrary code, due to incorrect handling of string

formatting in php_snmp_error() (bsc#977000)

This update was...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-626=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

apache2-mod_php5-5.5.14-47.1

apache2-mod_php5-debuginfo-5.5.14-47.1

php5-5.5.14-47.1

php5-bcmath-5.5.14-47.1

php5-bcmath-debuginfo-5.5.14-47.1

php5-bz2-5.5.14-47.1

php5-bz2-debuginfo-5.5.14-47.1

php5-calendar-5.5.14-47.1

php5-calendar-debuginfo-5.5.14-47.1

php5-ctype-5.5.14-47.1

php5-ctype-debuginfo-5.5.14-47.1

php5-curl-5.5.14-47.1

php5-curl-debuginfo-5.5.14-47.1

php5-dba-5.5.14-47.1

php5-dba-debuginfo-5.5.14-47.1

php5-debuginfo-5.5.14-47.1

php5-debugsource-5.5.14-47.1

php5-devel-5.5.14-47.1

php5-dom-5.5.14-47.1

php5-dom-debuginfo-5.5.14-47.1

php5-enchant-5.5.14-47.1

php5-enchant-debuginfo-5.5.14-47.1

php5-exif-5.5.14-47.1

php5-exif-debuginfo-5.5.14-47.1

php5-fastcgi-5.5.14-47.1

php5-fastcgi-debuginfo-5.5.14-47.1

php5-fileinfo-5.5.14-47.1

php5-fileinfo-debuginfo-5.5.14-47.1

php5-firebird-5.5.14-47.1

php5-firebird-debuginfo-5.5.14-47.1

php5-fpm-5.5.14-47.1

php5-fpm-debuginfo-5.5.14-47.1

php5-ftp-5.5.14-47.1

php5-ftp-debuginfo-5.5.14-47.1

php5-gd-5.5.14-47.1

php5-gd-debuginfo-5.5.14-47....

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2015-8866.html

https://www.suse.com/security/cve/CVE-2015-8867.html

https://www.suse.com/security/cve/CVE-2016-4070.html

https://www.suse.com/security/cve/CVE-2016-4071.html

https://www.suse.com/security/cve/CVE-2016-4073.html

https://bugzilla.suse.com/show_bug.cgi?id=976996

https://bugzilla.suse.com/show_bug.cgi?id=976997

https://bugzilla.suse.com/show_bug.cgi?id=977000

https://bugzilla.suse.com/show_bug.cgi?id=977003

https://bugzilla.suse.com/show_bug.cgi?id=977005

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:1373-1
Rating: important
Affected Products: openSUSE Leap 42.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.