Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: 2012:0840-1 Important: PHP5 Buffer Overflow Issues Fixed

suse
Calendar Grey July 5, 2012
Dist Suse Esm H88
A recent PHP5 upgrade addresses multiple security flaws impacting SUSE Linux platforms, with essential patches now made available.
An update that fixes four vulnerabilities is now available

Summary

PHP5 was updated with incremental fixes to the previous update. * CVE-2012-2335: Additional unsafe cgi wrapper scripts are also fixed now. * CVE-2012-2336: Even more commandline option handling is filtered, which could lead to crashes of the php interpreter. * CVE-2012-2386: heap based buffer overflow in php's phar extension * CVE-2012-2143: The crypt() implementation ignored wide characters, leading to shorter effective password lengths. Note: With this update applied affected passwords will no longer work and need to be set again. Security Issue references: * CVE-2012-2335 * CVE-2012-2336 * CVE-2012-2386

References

#761631 #763814 #766798

Cross- CVE-2012-2143 CVE-2012-2335 CVE-2012-2336

CVE-2012-2386

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

https://www.suse.com/security/cve/CVE-2012-2143.html

https://www.suse.com/security/cve/CVE-2012-2335.html

https://www.suse.com/security/cve/CVE-2012-2336.html

https://www.suse.com/security/cve/CVE-2012-2386.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0840-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here