Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2019:1725-1 Moderate: php7 Heap Overflow and Out-of-Bounds Fix

suse
Calendar Grey July 2, 2019
Dist Suse Esm H88
SUSE Security Patch for php8 tackles moderate severity vulnerabilities related to heap overflow and out-of-bounds access.
An update that solves two vulnerabilities and has one errata is now available

Summary

This update for php7 fixes the following issues: Security issues fixed: - CVE-2019-11039: Fixed a heap-buffer-overflow on php_jpg_get16 (bsc#1138173). - CVE-2019-11040: Fixed an out-of-bounds read due to an integer overflow in iconv.c:_php_iconv_mime_decode() (bsc#1138172). Other issue addressed: - Enable php7 testsuite (bsc#1119396 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-1725=1 - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2019-1725=1

References

#1119396 #1138172 #1138173

Cross- CVE-2019-11039 CVE-2019-11040

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Module for Web Scripting 12

https://www.suse.com/security/cve/CVE-2019-11039.html

https://www.suse.com/security/cve/CVE-2019-11040.html

https://bugzilla.suse.com/1119396

https://bugzilla.suse.com/1138172

https://bugzilla.suse.com/1138173

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1725-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here