Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE: 2015:1265-1 Important: PHP Type Confusion and Heap Overflow

suse
Calendar Grey July 17, 2015
Dist Suse Esm H88
SUSE PHP Security Patch 2015:1298-2 addresses several vulnerabilities, boosting the overall reliability and protection of the system.
An update that fixes 11 vulnerabilities is now available

Summary

The PHP script interpreter was updated to fix various security issues: * CVE-2015-4602 [bnc#935224]: Fixed an incomplete Class unserialization type confusion. * CVE-2015-4599, CVE-2015-4600, CVE-2015-4601 [bnc#935226]: Fixed type confusion issues in unserialize() with various SOAP methods. * CVE-2015-4603 [bnc#935234]: Fixed exception::getTraceAsString type confusion issue after unserialize. * CVE-2015-4644 [bnc#935274]: Fixed a crash in php_pgsql_meta_data. * CVE-2015-4643 [bnc#935275]: Fixed an integer overflow in ftp_genlist() that could result in a heap overflow. * CVE-2015-3411, CVE-2015-3412, CVE-2015-4598 [bnc#935227], [bnc#935232]: Added missing null byte checks for paths in various PHP extensions. * CVE-2015-4148 [bnc#933227]: Fixed a SoapClient's do_soap_call() type

References

#919080 #933227 #935074 #935224 #935226 #935227

#935232 #935234 #935274 #935275

Cross- CVE-2015-3411 CVE-2015-3412 CVE-2015-4148

CVE-2015-4598 CVE-2015-4599 CVE-2015-4600

CVE-2015-4601 CVE-2015-4602 CVE-2015-4603

CVE-2015-4643 CVE-2015-4644

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

https://www.suse.com/security/cve/CVE-2015-3411.html

https://www.suse.com/security/cve/CVE-2015-3412.html

https://www.suse.com/security/cve/CVE-2015-4148.html

https://www.suse.com/security/cve/CVE-2015-4598.html

https://www.suse.com/security/cve/CVE-2015-4599.html

https://www.suse.com/security/cve/CVE-2015-4600.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1265-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here