Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2019:0985-1 Moderate: Memory Access Vulnerabilities in php5

suse
Calendar Grey April 18, 2019
Dist Suse Esm H88
Revised SUSE Security Announcement SUSE-SU-2019:0985-1 regarding php5, tackling multiple severe memory access vulnerabilities.
An update that fixes 6 vulnerabilities is now available

Summary

This update for php5 fixes the following issues: Security issues fixed: - CVE-2019-9024: Fixed a vulnerability in xmlrpc_decode function which could allow to a hostile XMLRPC server to cause memory read outside the allocated areas (bsc#1126821). - CVE-2019-9020: Fixed a heap out of bounds in xmlrpc_decode function (bsc#1126711). - CVE-2018-20783: Fixed a buffer over-read in PHAR reading functions which could allow an attacker to read allocated and unallocated memory when parsing a phar file (bsc#1127122). - CVE-2019-9021: Fixed a heap buffer-based buffer over-read in PHAR reading functions which could allow an attacker to read allocated and unallocated memory when parsing a phar file (bsc#1126713). - CVE-2019-9023: Fixed multiple heap-based buffer over-read instances in

References

#1126711 #1126713 #1126821 #1126823 #1127122

#1128722

Cross- CVE-2018-20783 CVE-2019-9020 CVE-2019-9021

CVE-2019-9023 CVE-2019-9024 CVE-2019-9641

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Module for Web Scripting 12

https://www.suse.com/security/cve/CVE-2018-20783.html

https://www.suse.com/security/cve/CVE-2019-9020.html

https://www.suse.com/security/cve/CVE-2019-9021.html

https://www.suse.com/security/cve/CVE-2019-9023.html

https://www.suse.com/security/cve/CVE-2019-9024.html

https://www.suse.com/security/cve/CVE-2019-9641.html

https://bugzilla.suse.com/1126711

https://bugzilla.suse.com/1126713

https://bugzilla.suse.com/1126821

Announcement ID: SUSE-SU-2019:0985-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here