Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2019:1325-1 Moderate: PHP5 Buffer Overflow and Disclosure Fixes

suse
Calendar Grey May 23, 2019
Dist Suse Esm H88
The recent php5 patch addresses seven vulnerabilities, strengthening overall system defenses in SUSE Linux setups against possible security threats.
An update that fixes 8 vulnerabilities is now available

Summary

This update for php5 fixes the following issues: Security issues fixed: - CVE-2019-11034: Fixed a heap-buffer overflow in php_ifd_get32si() (bsc#1132838). - CVE-2019-11035: Fixed a heap-buffer overflow in exif_iif_add_value() (bsc#1132837). - CVE-2019-9637: Fixed a potential information disclosure in rename() (bsc#1128892). - CVE-2019-9675: Fixed a potential buffer overflow in phar_tar_writeheaders_int() (bsc#1128886). - CVE-2019-9638: Fixed an uninitialized read in exif_process_IFD_in_MAKERNOTE() related to value_len (bsc#1128889). - CVE-2019-9639: Fixed an uninitialized read in exif_process_IFD_in_MAKERNOTE() related to data_len (bsc#1128887). - CVE-2019-9640: Fixed an invalid Read in exif_process_SOFn() (bsc#1128883).

References

#1128883 #1128886 #1128887 #1128889 #1128892

#1132837 #1132838 #1134322

Cross- CVE-2019-11034 CVE-2019-11035 CVE-2019-11036

CVE-2019-9637 CVE-2019-9638 CVE-2019-9639

CVE-2019-9640 CVE-2019-9675

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Module for Web Scripting 12

https://www.suse.com/security/cve/CVE-2019-11034.html

https://www.suse.com/security/cve/CVE-2019-11035.html

https://www.suse.com/security/cve/CVE-2019-11036.html

https://www.suse.com/security/cve/CVE-2019-9637.html

https://www.suse.com/security/cve/CVE-2019-9638.html

https://www.suse.com/security/cve/CVE-2019-9639.html

https://www.suse.com/security/cve/CVE-2019-9640.html

Announcement ID: SUSE-SU-2019:1325-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here