Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

SUSE: 2016:2459-1 Important: Multiple Vulnerabilities in php53 Software

suse
Calendar Grey October 5, 2016
Dist Suse Esm H88
Important notice for SUSE Linux users regarding an update that resolves 16 critical vulnerabilities in php53, some of which are highly severe. Immediate action required!
An update that fixes 16 vulnerabilities is now available

Summary

This update for php53 fixes the following security issues: * CVE-2016-7124: Create an Unexpected Object and Don't Invoke __wakeup() in Deserialization * CVE-2016-7125: PHP Session Data Injection Vulnerability * CVE-2016-7126: select_colors write out-of-bounds * CVE-2016-7127: imagegammacorrect allowed arbitrary write access * CVE-2016-7128: Memory Leakage In exif_process_IFD_in_TIFF * CVE-2016-7129: wddx_deserialize allows illegal memory access * CVE-2016-7130: wddx_deserialize null dereference * CVE-2016-7131: wddx_deserialize null dereference with invalid xml * CVE-2016-7132: wddx_deserialize null dereference in php_wddx_pop_element * CVE-2016-7411: php5: Memory corruption when destructing deserialized object

References

#997206 #997207 #997208 #997210 #997211 #997220

#997225 #997230 #997257 #999679 #999680 #999682

#999684 #999685 #999819 #999820

Cross- CVE-2016-7124 CVE-2016-7125 CVE-2016-7126

CVE-2016-7127 CVE-2016-7128 CVE-2016-7129

CVE-2016-7130 CVE-2016-7131 CVE-2016-7132

CVE-2016-7411 CVE-2016-7412 CVE-2016-7413

CVE-2016-7414 CVE-2016-7416 CVE-2016-7417

CVE-2016-7418

Affected Products:

SUSE OpenStack Cloud 5

SUSE Manager Proxy 2.1

SUSE Manager 2.1

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debug...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2459-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here