Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE Leap 42.2: 2017:0588-1 Important: php7 Security Update

opensuse
Calendar Grey March 2, 2017
Dist Opensuse Esm H88
This critical enhancement addresses 15 vulnerabilities in php8, improving both reliability and protection for Fedora users.
An update that fixes 13 vulnerabilities is now available

Description

This update for php7 fixes the following security issues:

- CVE-2016-7480: The SplObjectStorage unserialize implementation in

ext/spl/spl_observer.c in PHP did not verify that a key is an object,

which allowed remote attackers to execute arbitrary code or cause a

denial

of service (uninitialized memory access) via crafted serialized data.

(bsc#1019568)

- CVE-2017-5340: Zend/zend_hash.c in PHP mishandled certain cases that

require large array allocations, which allowed remote attackers to

execute arbitrary code or cause a denial of service (integer overflow,

uninitialized memory access, and use of arbitrary destructor function

pointers) via crafted serialized data. (bsc#1019570)

- CVE-2016-7479: In all versions of PHP 7, during the unserialization

process, resizing the 'properties' hash table of a serialized object may

have lead to use-after-free. A remote attacker may exploit this bug to

gain arbitrary code...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2017-304=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.2 (i586 x86_64):

apache2-mod_php7-7.0.7-12.1

apache2-mod_php7-debuginfo-7.0.7-12.1

php7-7.0.7-12.1

php7-bcmath-7.0.7-12.1

php7-bcmath-debuginfo-7.0.7-12.1

php7-bz2-7.0.7-12.1

php7-bz2-debuginfo-7.0.7-12.1

php7-calendar-7.0.7-12.1

php7-calendar-debuginfo-7.0.7-12.1

php7-ctype-7.0.7-12.1

php7-ctype-debuginfo-7.0.7-12.1

php7-curl-7.0.7-12.1

php7-curl-debuginfo-7.0.7-12.1

php7-dba-7.0.7-12.1

php7-dba-debuginfo-7.0.7-12.1

php7-debuginfo-7.0.7-12.1

php7-debugsource-7.0.7-12.1

php7-devel-7.0.7-12.1

php7-dom-7.0.7-12.1

php7-dom-debuginfo-7.0.7-12.1

php7-enchant-7.0.7-12.1

php7-enchant-debuginfo-7.0.7-12.1

php7-exif-7.0.7-12.1

php7-exif-debuginfo-7.0.7-12.1

php7-fastcgi-7.0.7-12.1

php7-fastcgi-debuginfo-7.0.7-12.1

php7-fileinfo-7.0.7-12.1

php7-fileinfo-debuginfo-7.0.7-12.1

php7-firebird-7.0.7-12.1

php7-firebird-debuginfo-7.0.7-12.1

php7-fpm-7.0.7-12.1

php7-fpm-debuginfo-7.0.7-12.1

php7-ftp-7.0.7-12.1

php7-ftp-debuginfo-7.0.7-12.1

php7-gd-7.0.7-12.1

php7-gd-debuginfo-7.0.7-12.1

php7-gettext-7.0.7-12.1

php7-gettext...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2016-10158.html

https://www.suse.com/security/cve/CVE-2016-10159.html

https://www.suse.com/security/cve/CVE-2016-10160.html

https://www.suse.com/security/cve/CVE-2016-10161.html

https://www.suse.com/security/cve/CVE-2016-10162.html

https://www.suse.com/security/cve/CVE-2016-10166.html

https://www.suse.com/security/cve/CVE-2016-10167.html

https://www.suse.com/security/cve/CVE-2016-10168.html

https://www.suse.com/security/cve/CVE-2016-7478.html

https://www.suse.com/security/cve/CVE-2016-7479.html

https://www.suse.com/security/cve/CVE-2016-7480.html

https://www.suse.com/security/cve/CVE-2016-9138.html

https://www.suse.com/security/cve/CVE-2017-5340.html

https://bugzilla.suse.com/1008026

https://bugzilla.suse.com/1019547

https://bugzilla.suse.com/1019550

https://bugzilla.suse.com/1019568

https://bugzilla.suse.com/1019570

https://bugzilla.suse.com/1022219

https://bugzilla.suse.com/1022255

https://bugzilla.suse.com/1022257

https://bugzilla.suse.com/1022260

https://bugzilla.su...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2017:0588-1
Rating: important
Affected Products: openSUSE Leap 42.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here