Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE 42.3: 2019:1256-1 Moderate: php5 Memory Issues

opensuse
Calendar Grey April 23, 2019
Dist Opensuse Esm H88
This release for php5 resolves several memory concerns and important updates in openSUSE. Review the patch information now!
An update that fixes 6 vulnerabilities is now available.

Description

This update for php5 fixes the following issues:

Security issues fixed:

- CVE-2019-9024: Fixed a vulnerability in xmlrpc_decode function which

could allow to a hostile XMLRPC server to cause memory read outside the

allocated areas (bsc#1126821).

- CVE-2019-9020: Fixed a heap out of bounds in xmlrpc_decode function

(bsc#1126711).

- CVE-2018-20783: Fixed a buffer over-read in PHAR reading functions which

could allow an attacker to read allocated and unallocated memory when

parsing a phar file (bsc#1127122).

- CVE-2019-9021: Fixed a heap buffer-based buffer over-read in PHAR

reading functions which could allow an attacker to read allocated and

unallocated memory when parsing a phar file (bsc#1126713).

- CVE-2019-9023: Fixed multiple heap-based buffer over-read instances in

mbstring regular expression functions (bsc#1126823).

- CVE-2019-9641: Fixed multiple invalid memory access in EXIF extension

and improved insecure...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2019-1256=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

apache2-mod_php5-5.5.14-115.1

apache2-mod_php5-debuginfo-5.5.14-115.1

php5-5.5.14-115.1

php5-bcmath-5.5.14-115.1

php5-bcmath-debuginfo-5.5.14-115.1

php5-bz2-5.5.14-115.1

php5-bz2-debuginfo-5.5.14-115.1

php5-calendar-5.5.14-115.1

php5-calendar-debuginfo-5.5.14-115.1

php5-ctype-5.5.14-115.1

php5-ctype-debuginfo-5.5.14-115.1

php5-curl-5.5.14-115.1

php5-curl-debuginfo-5.5.14-115.1

php5-dba-5.5.14-115.1

php5-dba-debuginfo-5.5.14-115.1

php5-debuginfo-5.5.14-115.1

php5-debugsource-5.5.14-115.1

php5-devel-5.5.14-115.1

php5-dom-5.5.14-115.1

php5-dom-debuginfo-5.5.14-115.1

php5-enchant-5.5.14-115.1

php5-enchant-debuginfo-5.5.14-115.1

php5-exif-5.5.14-115.1

php5-exif-debuginfo-5.5.14-115.1

php5-fastcgi-5.5.14-115.1

php5-fastcgi-debuginfo-5.5.14-115.1

php5-fileinfo-5.5.14-115.1

php5-fileinfo-debuginfo-5.5.14-115.1

php5-firebird-5.5.14-115.1

php5-firebird-debuginfo-5.5.14-115.1

php5-fpm-5.5.14-115.1

php5-fpm-debuginfo-5.5.14-115.1

php5-ftp-5.5.14-115.1

php5-ftp-debuginfo-5.5.14-115.1

php5-gd-5.5.1...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-20783.html

https://www.suse.com/security/cve/CVE-2019-9020.html

https://www.suse.com/security/cve/CVE-2019-9021.html

https://www.suse.com/security/cve/CVE-2019-9023.html

https://www.suse.com/security/cve/CVE-2019-9024.html

https://www.suse.com/security/cve/CVE-2019-9641.html

https://bugzilla.suse.com/1126711

https://bugzilla.suse.com/1126713

https://bugzilla.suse.com/1126821

https://bugzilla.suse.com/1126823

https://bugzilla.suse.com/1127122

https://bugzilla.suse.com/1128722

--

Announcement ID: openSUSE-SU-2019:1256-1
Rating: moderate
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here