Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

SUSE 11-SP4: 2017:1709-1 Important: PHP53 Server Fix Against Threat

suse
Calendar Grey June 28, 2017
Dist Suse Esm H88
SUSE releases critical php53 updates to mitigate security vulnerabilities. Access the patch specifics and steps for installation here.
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is ...

Summary

This update for php53 fixes the following issues: - The fix for CVE-2017-7272 was reverted, as it caused regressions in the mysql server connect module. [bsc#1044976] The security fix tried to avoid a server side request forgery, and will be submitted when a better fix becomes available. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-php53-13179=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-php53-13179=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-13179=1 To bring your system up-to-date, use "zypper patch". Package List:

References

#1031246 #1044976

Cross- CVE-2017-7272

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2017-7272.html

https://bugzilla.suse.com/1031246

https://bugzilla.suse.com/1044976

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:1709-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here