Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for php5 fixes the following security issues: * CVE-2016-7411: php5: Memory corruption when destructing deserialized object * CVE-2016-7412: Heap overflow in mysqlnd when not receiving UNSIGNED_FLAG in BIT field * CVE-2016-7413: Use after free in wddx_deserialize * CVE-2016-7414: Out of bounds heap read when verifying signature of zip phar in phar_parse_zipfile * CVE-2016-7416: Stack based buffer overflow in msgfmt_format_message * CVE-2016-7417: Missing type check when unserializing SplArray * CVE-2016-7418: Null pointer dereference in php_wddx_push_element Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 12:
#999679 #999680 #999682 #999684 #999685 #999819
#999820
Cross- CVE-2016-7411 CVE-2016-7412 CVE-2016-7413
CVE-2016-7414 CVE-2016-7416 CVE-2016-7417
CVE-2016-7418
Affected Products:
SUSE Linux Enterprise Module for Web Scripting 12
https://www.suse.com/security/cve/CVE-2016-7411.html
https://www.suse.com/security/cve/CVE-2016-7412.html
https://www.suse.com/security/cve/CVE-2016-7413.html
https://www.suse.com/security/cve/CVE-2016-7414.html
https://www.suse.com/security/cve/CVE-2016-7416.html
https://www.suse.com/security/cve/CVE-2016-7417.html
https://www.suse.com/security/cve/CVE-2016-7418.html
https://bugzilla.suse.com/999679
https://bugzilla.suse.com/999680
https://bugzilla.suse.com/999682
https://bugzilla.suse.com/999684
Get the latest Linux and open source security news straight to your inbox.