This update for php7 fixes the following security issues:
- CVE-2016-7480: The SplObjectStorage unserialize implementation in
ext/spl/spl_observer.c in PHP did not verify that a key is an object,
which allowed remote attackers to execute arbitrary code or cause a
denial
of service (uninitialized memory access) via crafted serialized data.
(bsc#1019568)
- CVE-2017-5340: Zend/zend_hash.c in PHP mishandled certain cases that
require large array allocations, which allowed remote attackers to
execute arbitrary code or cause a denial of service (integer overflow,
uninitialized memory access, and use of arbitrary destructor function
pointers) via crafted serialized data. (bsc#1019570)
- CVE-2016-7479: In all versions of PHP 7, during the unserialization
process, resizing the 'properties' hash table of a serialized object may
have lead to use-after-free. A remote attacker may exploit this bug to
gain arbitrary code...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.2:
zypper in -t patch openSUSE-2017-304=1
To bring your system up-to-date, use "zypper patch".
- openSUSE Leap 42.2 (i586 x86_64):
apache2-mod_php7-7.0.7-12.1
apache2-mod_php7-debuginfo-7.0.7-12.1
php7-7.0.7-12.1
php7-bcmath-7.0.7-12.1
php7-bcmath-debuginfo-7.0.7-12.1
php7-bz2-7.0.7-12.1
php7-bz2-debuginfo-7.0.7-12.1
php7-calendar-7.0.7-12.1
php7-calendar-debuginfo-7.0.7-12.1
php7-ctype-7.0.7-12.1
php7-ctype-debuginfo-7.0.7-12.1
php7-curl-7.0.7-12.1
php7-curl-debuginfo-7.0.7-12.1
php7-dba-7.0.7-12.1
php7-dba-debuginfo-7.0.7-12.1
php7-debuginfo-7.0.7-12.1
php7-debugsource-7.0.7-12.1
php7-devel-7.0.7-12.1
php7-dom-7.0.7-12.1
php7-dom-debuginfo-7.0.7-12.1
php7-enchant-7.0.7-12.1
php7-enchant-debuginfo-7.0.7-12.1
php7-exif-7.0.7-12.1
php7-exif-debuginfo-7.0.7-12.1
php7-fastcgi-7.0.7-12.1
php7-fastcgi-debuginfo-7.0.7-12.1
php7-fileinfo-7.0.7-12.1
php7-fileinfo-debuginfo-7.0.7-12.1
php7-firebird-7.0.7-12.1
php7-firebird-debuginfo-7.0.7-12.1
php7-fpm-7.0.7-12.1
php7-fpm-debuginfo-7.0.7-12.1
php7-ftp-7.0.7-12.1
php7-ftp-debuginfo-7.0.7-12.1
php7-gd-7.0.7-12.1
php7-gd-debuginfo-7.0.7-12.1
php7-gettext-7.0.7-12.1
php7-gettext...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2016-10158.html
https://www.suse.com/security/cve/CVE-2016-10159.html
https://www.suse.com/security/cve/CVE-2016-10160.html
https://www.suse.com/security/cve/CVE-2016-10161.html
https://www.suse.com/security/cve/CVE-2016-10162.html
https://www.suse.com/security/cve/CVE-2016-10166.html
https://www.suse.com/security/cve/CVE-2016-10167.html
https://www.suse.com/security/cve/CVE-2016-10168.html
https://www.suse.com/security/cve/CVE-2016-7478.html
https://www.suse.com/security/cve/CVE-2016-7479.html
https://www.suse.com/security/cve/CVE-2016-7480.html
https://www.suse.com/security/cve/CVE-2016-9138.html
https://www.suse.com/security/cve/CVE-2017-5340.html
https://bugzilla.suse.com/1008026
https://bugzilla.suse.com/1019547
https://bugzilla.suse.com/1019550
https://bugzilla.suse.com/1019568
https://bugzilla.suse.com/1019570
https://bugzilla.suse.com/1022219
https://bugzilla.suse.com/1022255
https://bugzilla.suse.com/1022257
https://bugzilla.suse.com/1022260
https://bugzilla.su...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.