Moderate: php security update
Date: Fri, 12 Aug 2016 21:13:53 -0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
From: Kevin Hill
Subject: Security ERRATA Moderate: php on SL6.x i386/x86_64
MIME-Version: 1.0
Message-ID: <20160812211353.20354.36223@slpackages.fnal.gov>
Synopsis: Moderate: php security update
Advisory ID: SLSA-2016:1609-1
Issue Date: 2016-08-11
CVE Numbers: CVE-2016-5385
--
Security Fix(es):
* It was discovered that PHP did not properly protect against the
HTTP_PROXY variable name clash. A remote attacker could possibly use this
flaw to redirect HTTP requests performed by a PHP script to an attacker-
controlled proxy via a malicious HTTP request. (CVE-2016-5385)
--
SL6
x86_64
php-5.3.3-48.el6_8.x86_64.rpm
php-bcmath-5.3.3-48.el6_8.x86_64.rpm
php-cli-5.3.3-48.el6_8.x86_64.rpm
php-common-5.3.3-48.el6_8.x86_64.rpm
php-dba-5.3.3-48.el6_8.x86_64.rpm
php-debuginfo-5.3.3-48.el6_8.x86_64.rpm
php-devel-5.3.3-48.el6_8.x86_64.rpm
php-embedded-5.3.3-48.el6_8.x86_64.rpm
php-enchant-5.3.3-48.el6_8.x86_64.rpm
php-fpm-5.3.3-48.el6_8.x86_64.rpm
php-gd-5.3.3-48.el6_8.x86_64.rpm
php-imap-5.3.3-48.el6_8.x86_64.rpm
php-intl-5.3.3-48.el6_8.x86_64.rpm
php-ldap-5.3.3-48.el6_8.x86_64.rpm
php-mbstring-5.3.3-48.el6_8.x86_64.rpm
php-mysql-5.3.3-48.el6_8.x86_64.rpm
php-odbc-5.3.3-48.el6_8.x86_64.rpm
php-pdo-5.3.3-48.el6_8.x86_64.rpm
php-pgsql-5.3.3-48.el6_8.x86_64.rpm
php-process-5.3.3-48.el6_8.x86_64.rpm
php-pspell-5.3.3-48.el6_8.x86_64.rpm
php-recode-5.3.3-48.el6_8.x86_64.rpm
php-snmp-5.3.3-48.el6_8.x86_64.rpm
php-soap-5.3.3-48.el6_8.x86_64.rpm
php-tidy-5.3.3-48.el6_8.x86_64.rpm
php-xml-5.3.3-48.el6_8.x86_64.rpm
php-xmlrpc-5.3.3-48.el6_8.x86_64.rpm
php-zts-5.3.3-48.el6_8.x86_64.rpm
i386
php-5.3.3-48.el6_8.i686.rpm
php-bcmath-5.3.3-48.el6_8.i686.rpm
php-cli-5.3.3-48.el6_8.i686.rpm
php-common-5.3.3-48.el6_8.i686.rpm
php-dba-5.3.3-48.el6_8.i686.rpm
php-debuginfo-5.3.3-48.el6_8.i686.rpm
php-devel-5.3.3-48.el6_8.i686.rpm
php-embedded-5.3.3-48.el6_8.i686.rpm
php-enchant-5.3.3-48.el6_8.i686.rpm
php-fpm-5.3.3-48.el6_8.i686.rpm
php-gd-5.3.3-48.el6_8.i686.rpm
php-imap-5.3.3-48.el6_8.i686.rpm
php-intl-5.3.3-48.el6_8.i686.rpm
php-ldap-5.3.3-48.el6_8.i686.rpm
php-mbstring-5.3.3-48.el6_8.i686.rpm
php-mysql-5.3.3-48.el6_8.i686.rpm
php-odbc-5.3.3-48.el6_8.i686.rpm
php-pdo-5.3.3-48.el6_8.i686.rpm
php-pgsql-5.3.3-48.el6_8.i686.rpm
php-process-5.3.3-48.el6_8.i686.rpm
php-pspell-5.3.3-48.el6_8.i686.rpm
php-recode-5.3.3-48.el6_8.i686.rpm
php-snmp-5.3.3-48.el6_8.i686.rpm
php-soap-5.3.3-48.el6_8.i686.rpm
php-tidy-5.3.3-48.el6_8.i686.rpm
php-xml-5.3.3-48.el6_8.i686.rpm
php-xmlrpc-5.3.3-48.el6_8.i686.rpm
php-zts-5.3.3-48.el6_8.i686.rpm
- Scientific Linux Development Team