Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE: 2016:2080-1 Important: php5 Security Issues and Updates

suse
Calendar Grey August 16, 2016
Scroller Suse
SUSE Security Update for php7 addresses 15 vulnerabilities rated critical. Urgent update advised for impacted individuals.
An update that fixes 12 vulnerabilities is now available

Summary

php5 was updated to fix the following security issues: - CVE-2016-6297: Stack-based buffer overflow vulnerability in php_stream_zip_opener (bsc#991426). - CVE-2016-6291: Out-of-bounds access in exif_process_IFD_in_MAKERNOTE (bsc#991427). - CVE-2016-6289: Integer overflow leads to buffer overflow in virtual_file_ex (bsc#991428). - CVE-2016-6290: Use after free in unserialize() with Unexpected Session Deserialization (bsc#991429). - CVE-2016-5399: Improper error handling in bzread() (bsc#991430). - CVE-2016-6288: Buffer over-read in php_url_parse_ex (bsc#991433). - CVE-2016-6296: Heap buffer overflow vulnerability in simplestring_addn in simplestring.c (bsc#991437). - CVE-2016-5769: Mcrypt: Heap Overflow due to integer overflows (bsc#986388).

References

#986004 #986244 #986386 #986388 #986393 #991426

#991427 #991428 #991429 #991430 #991433 #991437

Cross- CVE-2015-8935 CVE-2016-5399 CVE-2016-5766

CVE-2016-5767 CVE-2016-5769 CVE-2016-5772

CVE-2016-6288 CVE-2016-6289 CVE-2016-6290

CVE-2016-6291 CVE-2016-6296 CVE-2016-6297

Affected Products:

SUSE Linux Enterprise Server 11-SP2-LTSS

SUSE Linux Enterprise Debuginfo 11-SP2

https://www.suse.com/security/cve/CVE-2015-8935.html

https://www.suse.com/security/cve/CVE-2016-5399.html

https://www.suse.com/security/cve/CVE-2016-5766.html

https://www.suse.com/security/cve/CVE-2016-5767.html

https://www.suse.com/security/cve/CVE-2016-5769.html

https://www.suse.com/security/cve/CVE-2016-5772.html

https://www.suse.com/security/cve/CVE-2016-6288.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2080-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.