For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the updated packages, the httpd daemon must be restarted
for the update to take effect.
PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.
The following packages have been upgraded to a later upstream version:
rh-php72-php (7.2.24). (BZ#1766603)
Security Fix(es):
* php: underflow in env_path_info in fpm_main.c (CVE-2019-11043)
* gd: Unsigned integer underflow _gdContributionsAlloc() (CVE-2016-10166)
* gd: Heap based buffer overflow in gdImageColorMatch() in gd_color_match.c
(CVE-2019-6977)
* php: Invalid memory access in function xmlrpc_decode() (CVE-2019-9020)
* php: File rename across filesystems may allow unwanted access during
processing (CVE-2019-9637)
* php: Uninitialized read in exif_process_IFD_in_MAKERNOTE (CVE-2019-9638)
* php: Uninitialized read in exif_process_IFD_in_MAKERNOTE (CVE-2019-9639)
* php: Invalid read in exif_process_SOFn() (CVE-2019-9640)
* php: Out-of-bounds read due to integer overflow in
iconv_mime_decode_headers() (CVE-2019-11039)
* php: Buffer over-read in exif_read_data() (CVE-2019-11040)
* php: Buffer over-read in PHAR reading functions (CVE-2018-20783)
* php: Heap-based buffer over-read in PHAR reading functions
(CVE-2019-9021)
* php: memcpy with negative length via crafted DNS response (CVE-2019-9022)
* php: Heap-based buffer over-read in mbstring regular expression functions
(CVE-2019-9023)
* php: Out-of-bounds read in base64_decode_xmlrpc in
ext/xmlrpc/libxmlrpc/base64.c (CVE-2019-9024)
* php: Heap buffer overflow in function exif_process_IFD_TAG()
(CVE-2019-11034)
* php: Heap buffer overflow in function exif_iif_add_value()
(CVE-2019-11035)
* php: Buffer over-read in exif_process_IFD_TAG() leading to information
disclosure (CVE-2019-11036)
* gd: Information disclosure in gdImageCreateFromXbm() (CVE-2019-11038)
* php: heap buffer over-read in exif_scan_thumbnail() (CVE-2019-11041)
* php: heap buffer over-read in exif_process_user_comment()
(CVE-2019-11042)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2016-10166 https://access.redhat.com/security/cve/CVE-2018-20783 https://access.redhat.com/security/cve/CVE-2019-6977 https://access.redhat.com/security/cve/CVE-2019-9020 https://access.redhat.com/security/cve/CVE-2019-9021 https://access.redhat.com/security/cve/CVE-2019-9022 https://access.redhat.com/security/cve/CVE-2019-9023 https://access.redhat.com/security/cve/CVE-2019-9024 https://access.redhat.com/security/cve/CVE-2019-9637 https://access.redhat.com/security/cve/CVE-2019-9638 https://access.redhat.com/security/cve/CVE-2019-9639 https://access.redhat.com/security/cve/CVE-2019-9640 https://access.redhat.com/security/cve/CVE-2019-11034 https://access.redhat.com/security/cve/CVE-2019-11035 https://access.redhat.com/security/cve/CVE-2019-11036 https://access.redhat.com/security/cve/CVE-2019-11038 https://access.redhat.com/security/cve/CVE-2019-11039 https://access.redhat.com/security/cve/CVE-2019-11040 https://access.redhat.com/security/cve/CVE-2019-11041 https://access.redhat.com/security/cve/CVE-2019-11042 https://access.redhat.com/security/cve/CVE-2019-11043 https://access.redhat.com/security/updates/classification#critical
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source:
rh-php72-php-7.2.24-1.el7.src.rpm
aarch64:
rh-php72-php-7.2.24-1.el7.aarch64.rpm
rh-php72-php-bcmath-7.2.24-1.el7.aarch64.rpm
rh-php72-php-cli-7.2.24-1.el7.aarch64.rpm
rh-php72-php-common-7.2.24-1.el7.aarch64.rpm
rh-php72-php-dba-7.2.24-1.el7.aarch64.rpm
rh-php72-php-dbg-7.2.24-1.el7.aarch64.rpm
rh-php72-php-debuginfo-7.2.24-1.el7.aarch64.rpm
rh-php72-php-devel-7.2.24-1.el7.aarch64.rpm
rh-php72-php-embedded-7.2.24-1.el7.aarch64.rpm
rh-php72-php-enchant-7.2.24-1.el7.aarch64.rpm
rh-php72-php-fpm-7.2.24-1.el7.aarch64.rpm
rh-php72-php-gd-7.2.24-1.el7.aarch64.rpm
rh-php72-php-gmp-7.2.24-1.el7.aarch64.rpm
rh-php72-php-intl-7.2.24-1.el7.aarch64.rpm
rh-php72-php-json-7.2.24-1.el7.aarch64.rpm
rh-php72-php-ldap-7.2.24-1.el7.aarch64.rpm
rh-php72-php-mbstring-7.2.24-1.el7.aarch64.rpm
rh-php72-php-mysqlnd-7.2.24-1.el7.aarch64.rpm
rh-php72-php-odbc-7.2.24-1.el7.aarch64.rpm
rh-php72-php-opcache-7.2.24-1.el7.aarch64.rpm
rh-php72-php-pdo-7.2.24-1.el7.aarch64.rpm
rh-php72-php-pgsql-7.2.24-1.el7.aarch64.rpm
rh-php72-php-process-7.2.24-1.el7.aarch64.rpm
rh-php72-php-pspell-7.2.24-1.el7.aarch64.rpm
rh-php72-php-recode-7.2.24-1.el7.aarch64.rpm
Read the Full Advisory
An update for rh-php72-php is now available for Red Hat Software
Collections.
Red Hat Product Security has rated this update as having a security impact
of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64
1418983 - CVE-2016-10166 gd: Unsigned integer underflow _gdContributionsAlloc()
1672207 - CVE-2019-6977 gd: Heap based buffer overflow in gdImageColorMatch() in gd_color_match.c
1680545 - CVE-2018-20783 php: Buffer over-read in PHAR reading functions
1685123 - CVE-2019-9020 php: Invalid memory access in function xmlrpc_decode()
1685132 - CVE-2019-9021 php: Heap-based buffer over-read in PHAR reading functions
1685398 - CVE-2019-9023 php: Heap-based buffer over-read in mbstring regular expression functions
1685404 - CVE-2019-9024 php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c
1685412 - CVE-2019-9022 php: memcpy with negative length via crafted DNS response
1688897 - CVE-2019-9637 php: File rename across filesystems may allow unwanted access during processing
1688922 - CVE-2019-9638 php: Uninitialized read in exif_process_IFD_in_MAKERNOTE
1688934 - CVE-2019-9639 php: Uninitialized read in exif_process_IFD_in_MAKERNOTE
1688939 - CVE-2019-9640 php: Invalid read in exif_process_SOFn()
1702246 - CVE-2019-11035 php: Heap buffer overflow in function exif_iif_add_value()
1702256 - CVE-2019-11034 php: Heap buffer overflow in function exif_process_IFD_TAG()
1707299 - CVE-2019-11036 php: Buffer over-read in exif_process_IFD_TAG() leading to information disclosure
1724149 - CVE-2019-11038 gd: Information disclosure in gdImageCreateFromXbm()
Get the latest Linux and open source security news straight to your inbox.