Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE: 2020:0522-1 Moderate: php5 Remote Code Execution and More

suse
Calendar Grey February 28, 2020
Dist Suse Esm H88
The latest php5 update fixes serious security issues, addressing remote code execution threats alongside other concerns. Check the official announcement for full details
An update that solves 9 vulnerabilities and has one errata is now available

Summary

This update for php5 fixes the following issues: Security issues fixed: - CVE-2019-11041: Fixed heap buffer over-read in exif_scan_thumbnail() (bsc#1146360). - CVE-2019-11042: Fixed heap buffer over-read in exif_process_user_comment() (bsc#1145095). - CVE-2019-11043: Fixed possible remote code execution via env_path_info underflow in fpm_main.c (bsc#1154999). - CVE-2019-11045: Fixed an issue with the PHP DirectoryIterator class that accepts filenames with embedded \0 bytes (bsc#1159923). - CVE-2019-11046: Fixed an out-of-bounds read in bc_shift_addsub (bsc#1159924). - CVE-2019-11047: Fixed an information disclosure in exif_read_data (bsc#1159922). - CVE-2019-11050: Fixed a buffer over-read in the EXIF extension (bsc#1159927).

References

#1145095 #1146360 #1154999 #1159922 #1159923

#1159924 #1159927 #1161982 #1162629 #1162632

Cross- CVE-2019-11041 CVE-2019-11042 CVE-2019-11043

CVE-2019-11045 CVE-2019-11046 CVE-2019-11047

CVE-2019-11050 CVE-2020-7059 CVE-2020-7060

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Module for Web Scripting 12

https://www.suse.com/security/cve/CVE-2019-11041.html

https://www.suse.com/security/cve/CVE-2019-11042.html

https://www.suse.com/security/cve/CVE-2019-11043.html

https://www.suse.com/security/cve/CVE-2019-11045.html

https://www.suse.com/security/cve/CVE-2019-11046.html

https://www.suse.com/security/cve/CVE-2019-11047.html

https://www.suse.com/security/cve/CVE-2019-11050.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0522-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here