Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

SUSE 11 SP2: 2012:0598-2 Critical: PHP5 Command Injection & Traversal

suse
Calendar Grey May 9, 2012
Scroller Suse
Essential security enhancement for PHP5 in openSUSE Linux tackling various vulnerabilities. Confirm installation of updates for safeguarding.
An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now available

Summary

This update fixes several security issues in PHP5: * CVE-2012-1172: A directory traversal bug has been fixed in PHP5. * CVE-2012-1823, CVE-2012-2311: A command injection was possible when PHP5 was operated in CGI mode using commandline options. This problem does not affect PHP5 in the normal apache module mode setup. * Also a pack/unpacking bug on big endian 64bit architectures (ppc64 and s390x) has been fixed. bnc#753778 Security Issue references: * CVE-2012-1172 * CVE-2012-1823 * CVE-2012-2311 Patch Instructions: To install this SUSE Security Update use YaST online_update.

References

#752030 #753778 #760536

Cross- CVE-2012-1172 CVE-2012-1823 CVE-2012-2311

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Software Development Kit 11 SP1

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Server 11 SP1 for VMware

SUSE Linux Enterprise Server 11 SP1

https://www.suse.com/security/cve/CVE-2012-1172.html

https://www.suse.com/security/cve/CVE-2012-1823.html

https://www.suse.com/security/cve/CVE-2012-2311.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0598-2
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.