Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2012:0604-2 Urgent: PHP5 Remote Code Execution And File Inclusion

suse
Calendar Grey May 9, 2012
Dist Suse Esm H88
SUSE announces a vital security patch for PHP5, affecting SUSE Linux platforms. Apply the update immediately!
An update that fixes three vulnerabilities is now available

Summary

This update fixes several security issues in PHP5: * CVE-2012-1172: A directory traversal bug has been fixed in PHP5 * CVE-2012-1823, CVE-2012-2311: A command injection was possible when PHP5 was operated in CGI mode using commandline options. This problem does not affect PHP5 in the normal Apache module mode setup. Security Issue references: * CVE-2012-1172 * CVE-2012-1823 * CVE-2012-2311 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP2:

References

#752030 #760536

Cross- CVE-2012-1172 CVE-2012-1823 CVE-2012-2311

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

https://www.suse.com/security/cve/CVE-2012-1172.html

https://www.suse.com/security/cve/CVE-2012-1823.html

https://www.suse.com/security/cve/CVE-2012-2311.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0604-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here