Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE: 2012:0472-1 Important: PHP5 Denial Of Service Threat

suse
Calendar Grey April 6, 2012
Scroller Suse
SUSE has released a security patch for PHP5 that addresses four vulnerabilities, including problems related to denial of service and the potential for unauthorized code execution.
An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one An update that solves four vulnerabilities and has one errata is now a...

Summary

This update of PHP5 fixes multiple security flaws: * CVE-2011-4153, missing checks of return values could allow remote attackers to cause a denial of service (NULL pointer dereference) * CVE-2012-0057, specially crafted XSLT stylesheets could allow remote attackers to create arbitrary files with arbitrary content * CVE-2012-0807, a stack based buffer overflow in php5's Suhosin extension could allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header * CVE-2012-0831, temporary changes to the magic_quotes_gpc directive during the importing of environment variables is not properly performed which makes it easier for remote attackers to conduct SQL injections Security Issue references: * CVE-2011-4153

References

#741520 #741859 #743308 #746661 #749111

Cross- CVE-2011-4153 CVE-2012-0057 CVE-2012-0807

CVE-2012-0831

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

https://www.suse.com/security/cve/CVE-2011-4153.html

https://www.suse.com/security/cve/CVE-2012-0057.html

https://www.suse.com/security/cve/CVE-2012-0807.html

https://www.suse.com/security/cve/CVE-2012-0831.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0472-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.