Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE Linux: 2015:1253-1 Important: php5 DoS And Memory Issues

suse
Calendar Grey July 17, 2015
Scroller Suse
SUSE's php7 upgrade addresses 18 security flaws, boosting protection for users and resolving key software bugs.
An update that fixes 15 vulnerabilities is now available

Summary

This security update of PHP fixes the following issues: Security issues fixed: * CVE-2015-4024 [bnc#931421]: Fixed multipart/form-data remote DOS Vulnerability. * CVE-2015-4026 [bnc#931776]: pcntl_exec() did not check path validity. * CVE-2015-4022 [bnc#931772]: Fixed and overflow in ftp_genlist() that resulted in a heap overflow. * CVE-2015-4021 [bnc#931769]: Fixed memory corruption in phar_parse_tarfile when entry filename starts with NULL. * CVE-2015-4148 [bnc#933227]: Fixed SoapClient's do_soap_call() type confusion after unserialize() information disclosure. * CVE-2015-4602 [bnc#935224]: Fixed an incomplete Class unserialization type confusion. * CVE-2015-4599, CVE-2015-4600, CVE-2015-4601 [bnc#935226]: Fixed type confusion issues in unserialize() with various SOAP methods.

References

#919080 #927147 #931421 #931769 #931772 #931776

#933227 #935224 #935226 #935227 #935232 #935234

#935274 #935275

Cross- CVE-2015-3411 CVE-2015-3412 CVE-2015-4021

CVE-2015-4022 CVE-2015-4024 CVE-2015-4026

CVE-2015-4148 CVE-2015-4598 CVE-2015-4599

CVE-2015-4600 CVE-2015-4601 CVE-2015-4602

CVE-2015-4603 CVE-2015-4643 CVE-2015-4644

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Module for Web Scripting 12

https://www.suse.com/security/cve/CVE-2015-3411.html

https://www.suse.com/security/cve/CVE-2015-3412.html

https://www.suse.com/security/cve/CVE-2015-4021.html

https://www.suse.com/security/cve/CVE-2015-4022.html

https://www.suse.com/security/cve/CVE-2015-4024.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1253-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.