Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the updated packages, the httpd daemon must be restarted
for the update to take effect.
PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. The rh-php56 packages provide a recent stable release of PHP
with PEAR 1.9.5 and enhanced language features including constant
expressions, variadic functions, arguments unpacking, and the interactive
debuger. The memcache, mongo, and XDebug extensions are also included.
The rh-php56 Software Collection has been upgraded to version 5.6.25, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1356157, BZ#1365401)
Security Fixes in the rh-php56-php component:
* Several Moderate and Low impact security issues were found in PHP. Under
certain circumstances, these issues could cause PHP to crash, disclose
portions of its memory, execute arbitrary code, or impact PHP application
integrity. Space precludes documenting each of these issues in this
advisory. Refer to the CVE links in the References section for a
description of each of these vulnerabilities. (CVE-2013-7456,
CVE-2014-9767, CVE-2015-8835, CVE-2015-8865, CVE-2015-8866, CVE-2015-8867,
CVE-2015-8873, CVE-2015-8874, CVE-2015-8876, CVE-2015-8877, CVE-2015-8879,
CVE-2016-1903, CVE-2016-2554, CVE-2016-3074, CVE-2016-3141, CVE-2016-3142,
CVE-2016-4070, CVE-2016-4071, CVE-2016-4072, CVE-2016-4073, CVE-2016-4342,
CVE-2016-4343, CVE-2016-4473, CVE-2016-4537, CVE-2016-4538, CVE-2016-4539,
CVE-2016-4540, CVE-2016-4541, CVE-2016-4542, CVE-2016-4543, CVE-2016-4544,
CVE-2016-5093, CVE-2016-5094, CVE-2016-5096, CVE-2016-5114, CVE-2016-5399,
CVE-2016-5766, CVE-2016-5767, CVE-2016-5768, CVE-2016-5770, CVE-2016-5771,
CVE-2016-5772, CVE-2016-5773, CVE-2016-6128, CVE-2016-6207, CVE-2016-6288,
CVE-2016-6289, CVE-2016-6290, CVE-2016-6291, CVE-2016-6292, CVE-2016-6294,
CVE-2016-6295, CVE-2016-6296, CVE-2016-6297, CVE-2016-7124, CVE-2016-7125,
CVE-2016-7126, CVE-2016-7127, CVE-2016-7128, CVE-2016-7129, CVE-2016-7130,
CVE-2016-7131, CVE-2016-7132)
* Multiple flaws were found in the PCRE library included with the
rh-php56-php packages for Red Hat Enterprise Linux 6. A specially crafted
regular expression could cause PHP to crash or, possibly, execute arbitrary
code. (CVE-2015-2325, CVE-2015-2326, CVE-2015-2327, CVE-2015-2328,
CVE-2015-3210, CVE-2015-3217, CVE-2015-5073, CVE-2015-8381, CVE-2015-8383,
CVE-2015-8384, CVE-2015-8385, CVE-2015-8386, CVE-2015-8388, CVE-2015-8391,
CVE-2015-8392, CVE-2015-8395)
Red Hat would like to thank Hans Jerry Illikainen for reporting
CVE-2016-3074, CVE-2016-4473, and CVE-2016-5399.
https://access.redhat.com/security/cve/CVE-2013-7456 https://access.redhat.com/security/cve/CVE-2014-9767 https://access.redhat.com/security/cve/CVE-2015-2325 https://access.redhat.com/security/cve/CVE-2015-2326 https://access.redhat.com/security/cve/CVE-2015-2327 https://access.redhat.com/security/cve/CVE-2015-2328 https://access.redhat.com/security/cve/CVE-2015-3210 https://access.redhat.com/security/cve/CVE-2015-3217 https://access.redhat.com/security/cve/CVE-2015-5073 https://access.redhat.com/security/cve/CVE-2015-8381 https://access.redhat.com/security/cve/CVE-2015-8383 https://access.redhat.com/security/cve/CVE-2015-8384 https://access.redhat.com/security/cve/CVE-2015-8385 https://access.redhat.com/security/cve/CVE-2015-8386 https://access.redhat.com/security/cve/CVE-2015-8388 https://access.redhat.com/security/cve/CVE-2015-8391 https://access.redhat.com/security/cve/CVE-2015-8392 https://access.redhat.com/security/cve/CVE-2015-8395 https://access.redhat.com/security/cve/CVE-2015-8835 https://access.redhat.com/security/cve/CVE-2015-8865 https://access.redhat.com/security/cve/CVE-2015-8866 https://access.redhat.com/security/cve/CVE-2015-8867 https://access.redhat.com/security/cve/CVE-2015-8873 https://access.redhat.com/security/cve/CVE-2015-8874 Read the Full Advisory
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6):
Source:
rh-php56-2.3-1.el6.src.rpm
rh-php56-php-5.6.25-1.el6.src.rpm
rh-php56-php-pear-1.9.5-4.el6.src.rpm
noarch:
rh-php56-php-pear-1.9.5-4.el6.noarch.rpm
x86_64:
rh-php56-2.3-1.el6.x86_64.rpm
rh-php56-php-5.6.25-1.el6.x86_64.rpm
rh-php56-php-bcmath-5.6.25-1.el6.x86_64.rpm
rh-php56-php-cli-5.6.25-1.el6.x86_64.rpm
rh-php56-php-common-5.6.25-1.el6.x86_64.rpm
rh-php56-php-dba-5.6.25-1.el6.x86_64.rpm
rh-php56-php-dbg-5.6.25-1.el6.x86_64.rpm
rh-php56-php-debuginfo-5.6.25-1.el6.x86_64.rpm
rh-php56-php-devel-5.6.25-1.el6.x86_64.rpm
rh-php56-php-embedded-5.6.25-1.el6.x86_64.rpm
rh-php56-php-enchant-5.6.25-1.el6.x86_64.rpm
rh-php56-php-fpm-5.6.25-1.el6.x86_64.rpm
rh-php56-php-gd-5.6.25-1.el6.x86_64.rpm
rh-php56-php-gmp-5.6.25-1.el6.x86_64.rpm
rh-php56-php-imap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-intl-5.6.25-1.el6.x86_64.rpm
rh-php56-php-ldap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-mbstring-5.6.25-1.el6.x86_64.rpm
rh-php56-php-mysqlnd-5.6.25-1.el6.x86_64.rpm
rh-php56-php-odbc-5.6.25-1.el6.x86_64.rpm
rh-php56-php-opcache-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pdo-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pgsql-5.6.25-1.el6.x86_64.rpm
rh-php56-php-process-5.6.25-1.el6.x86_64.rpm
Read the Full Advisory
An update for rh-php56, rh-php56-php, and rh-php56-php-pear is nowavailable for Red Hat Software Collections.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.2) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
1207198 - CVE-2015-2325 pcre: heap buffer overflow in compile_branch()
1207202 - CVE-2015-2326 pcre: heap buffer over-read in pcre_compile2() (8.37/23)
1228283 - CVE-2015-3217 pcre: stack overflow caused by mishandled group empty match (8.38/11)
1237223 - CVE-2015-5073 CVE-2015-8388 pcre: buffer overflow for forward reference within backward assertion with excess closing parenthesis (8.38/18)
1260716 - CVE-2014-9767 php: ZipArchive::extractTo allows for directory traversal when creating directories
1285399 - CVE-2015-2328 pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
1285408 - CVE-2015-2327 pcre: infinite recursion compiling pattern with zero-repeated groups that include recursive back reference (8.36/19)
1287614 - CVE-2015-8383 pcre: Buffer overflow caused by repeated conditional group (8.38/3)
1287623 - CVE-2015-3210 CVE-2015-8384 pcre: buffer overflow caused by recursive back reference by name within certain group (8.38/4)
1287629 - CVE-2015-8385 pcre: buffer overflow caused by named forward reference to duplicate group number (8.38/30)
1287636 - CVE-2015-8386 pcre: Buffer overflow caused by lookbehind assertion (8.38/6)
1287671 - CVE-2015-8391 pcre: inefficient posix character class syntax check (8.38/16)
1287690 - CVE-2015-8392 pcre: buffer overflow caused by patterns with duplicated named groups with (?| (8.38/27)
Get the latest Linux and open source security news straight to your inbox.