Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2014:0870-1 Critical: OpenSSL Security Vulnerability Exploit

suse
Calendar Grey July 4, 2014
Scroller Suse
Addresses two major vulnerabilities in PHP5 for SUSE Linux. Ensure your systems are protected by applying this crucial update promptly.
An update that fixes two vulnerabilities is now available

Summary

PHP5 has been updated to fix two security vulnerabilities: * Heap-based buffer overflow in DNS TXT record parsing (CVE-2014-4049) * NULL pointer dereference in GD XPM decoder (CVE-2014-2497) Security Issue references: * CVE-2014-4049 * CVE-2014-2497 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP2 LTSS: zypper in -t patch slessp2-apache2-mod_php5-9409 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP2 LTSS (i586 s390x x86_64): apache2-mod_php5-5.2.14-0.7.30.54.1

References

#868624 #882992

Cross- CVE-2014-2497 CVE-2014-4049

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

https://www.suse.com/security/cve/CVE-2014-2497.html

https://www.suse.com/security/cve/CVE-2014-4049.html

https://login.microfocus.com/nidp/app/login?sid=0

https://login.microfocus.com/nidp/app/login?sid=0

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0868-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.