Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2016:1638-1 Important: php53 Critical Update for DoS Issues

suse
Calendar Grey June 21, 2016
Dist Suse Esm H88
Essential patch for php53 on SUSE resolving 85 vulnerabilities. Key improvements for system reliability and protection.
An update that fixes 85 vulnerabilities is now available

Summary

This update for php53 to version 5.3.17 fixes the following issues: These security issues were fixed: - CVE-2016-5093: get_icu_value_internal out-of-bounds read (bnc#982010). - CVE-2016-5094: Don't create strings with lengths outside int range (bnc#982011). - CVE-2016-5095: Don't create strings with lengths outside int range (bnc#982012). - CVE-2016-5096: int/size_t confusion in fread (bsc#982013). - CVE-2016-5114: fpm_log.c memory leak and buffer overflow (bnc#982162). - CVE-2015-8879: The odbc_bindcols function in ext/odbc/php_odbc.c in PHP mishandles driver behavior for SQL_WVARCHAR columns, which allowed remote attackers to cause a denial of service (application crash) in opportunistic circumstances by leveraging use of the odbc_fetch_array

References

#884986 #884987 #884989 #884990 #884991 #884992

#885961 #886059 #886060 #893849 #893853 #902357

#902360 #902368 #910659 #914690 #917150 #918768

#919080 #921950 #922451 #922452 #923945 #924972

#925109 #928506 #928511 #931421 #931769 #931772

#931776 #933227 #935074 #935224 #935226 #935227

#935229 #935232 #935234 #935274 #935275 #938719

#938721 #942291 #942296 #945412 #945428 #949961

#968284 #969821 #971611 #971612 #971912 #973351

#973792 #976996 #976997 #977003 #977005 #977991

#977994 #978827 #978828 #978829 #978830 #980366

#980373 #980375 #981050 #982010 #982011 #982012

#982013 #982162

Cross- CVE-2004-1019 CVE-2006-7243 CVE-2014-0207

CVE-2014-3478 CVE-2014-3479 CVE-2014-3480

CVE-2014-3487 CVE-2014-35...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1638-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here