Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

SUSE: 2016:2328-1 Critical: PHP53 Buffer Overflow Security Update

suse
Calendar Grey September 16, 2016
Dist Suse Esm H88
SUSE Security Patch for php7 addresses urgent concerns with 20 weaknesses, bolstering overall system protection.
An update that fixes 18 vulnerabilities is now available

Summary

This update for php53 fixes the following security issues: * CVE-2014-3587: Integer overflow in the cdf_read_property_info affecting SLES11 SP3 [bsc#987530] * CVE-2016-6297: Stack-based buffer overflow vulnerability in php_stream_zip_opener [bsc#991426] * CVE-2016-6291: Out-of-bounds access in exif_process_IFD_in_MAKERNOTE [bsc#991427] * CVE-2016-6289: Integer overflow leads to buffer overflow in virtual_file_ex [bsc#991428] * CVE-2016-6290: Use after free in unserialize() with Unexpected Session Deserialization [bsc#991429] * CVE-2016-5399: Improper error handling in bzread() [bsc#991430] * CVE-2016-6288: Buffer over-read in php_url_parse_ex [bsc#991433] * CVE-2016-6296: Heap buffer overflow vulnerability in simplestring_addn in simplestring.c [bsc#991437]

References

#987530 #991426 #991427 #991428 #991429 #991430

#991433 #991437 #997206 #997207 #997208 #997210

#997211 #997220 #997225 #997230 #997257

Cross- CVE-2014-3587 CVE-2016-3587 CVE-2016-5399

CVE-2016-6288 CVE-2016-6289 CVE-2016-6290

CVE-2016-6291 CVE-2016-6296 CVE-2016-6297

CVE-2016-7124 CVE-2016-7125 CVE-2016-7126

CVE-2016-7127 CVE-2016-7128 CVE-2016-7129

CVE-2016-7130 CVE-2016-7131 CVE-2016-7132

Affected Products:

SUSE Linux Enterprise Server 11-SP2-LTSS

SUSE Linux Enterprise Debuginfo 11-SP2

https://www.suse.com/security/cve/CVE-2014-3587.html

https://www.suse.com/security/cve/CVE-2016-3587.html

https://www.suse.com/security/cve/CVE-2016-5399.html

https://www.suse.com/security/cve/CVE-2016-6288.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2328-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here