Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

SUSE Linux: 2015:1633-1 Important: PHP5 Remote Code Execution Issues

suse
Calendar Grey September 25, 2015
Scroller Suse
Essential SUSE php5 security notice addressing 8 vulnerabilities, featuring remote code execution flaws and various issues.
An update that solves 8 vulnerabilities and has three fixes An update that solves 8 vulnerabilities and has three fixes An update that solves 8 vulnerabilities and has three fixes ...

Summary

This update of PHP5 brings several security fixes. Security fixes: * CVE-2015-6831: A use after free vulnerability in unserialize() has been fixed which could be used to crash php or potentially execute code. [bnc#942291] [bnc#942294] [bnc#942295] * CVE-2015-6832: A dangling pointer in the unserialization of ArrayObject items could be used to crash php or potentially execute code. [bnc#942293] * CVE-2015-6833: A directory traversal when extracting ZIP files could be used to overwrite files outside of intended area. [bnc#942296] * CVE-2015-6834: A Use After Free Vulnerability in unserialize() has been fixed which could be used to crash php or potentially execute code. [bnc#945403] * CVE-2015-6835: A Use After Free Vulnerability in session unserialize()

References

#935074 #942291 #942293 #942294 #942295 #942296

#944302 #945402 #945403 #945412 #945428

Cross- CVE-2015-6831 CVE-2015-6832 CVE-2015-6833

CVE-2015-6834 CVE-2015-6835 CVE-2015-6836

CVE-2015-6837 CVE-2015-6838

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Module for Web Scripting 12

https://www.suse.com/security/cve/CVE-2015-6831.html

https://www.suse.com/security/cve/CVE-2015-6832.html

https://www.suse.com/security/cve/CVE-2015-6833.html

https://www.suse.com/security/cve/CVE-2015-6834.html

https://www.suse.com/security/cve/CVE-2015-6835.html

https://www.suse.com/security/cve/CVE-2015-6836.html

https://www.suse.com/security/cve/CVE-2015-6837.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1633-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.