Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 79 articles for you...
100

SUSE: 2020:2894-1 Important: php5 Cookie Overwrite Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php5 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2894-1 Rating: important References: #1177352 Cross-References: CVE-2020-7070 Affected Products: SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php5 fixes the following issues: - CVE-2020-7070: Fixed an issue where percent-encoded cookies could have been used to overwrite existing prefixed cookie names (bsc#1177352). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-2894=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php5-5.5.14-109.82.1 apache2-mod_php5-debuginfo-5.5.14-109.82.1 php5-5.5.14-109.82.1 php5-bcmath-5.5.14-109.82.1 php5-bcmath-debuginfo-5.5.14-109.82.1 php5-bz2-5.5.14-109.82.1 php5-bz2-debuginfo-5.5.14-109.82.1 php5-calendar-5.5.14-109.82.1 php5-calendar-debuginfo-5.5.14-109.82.1 php5-ctype-5.5.14-109.82.1 php5-ctype-debuginfo-5.5.14-109.82.1 php5-curl-5.5.14-109.82.1 php5-curl-debuginfo-5.5.14-109.82.1 php5-dba-5.5.14-109.82.1 php5-dba-debuginfo-5.5.14-109.82.1 php5-debuginfo-5.5.14-109.82.1 php5-debugsource-5.5.14-109.82.1 php5-dom-5.5.14-109.82.1 php5-dom-debuginfo-5.5.14-109.82.1 php5-enchant-5.5.14-109.82.1 php5-enchant-debuginfo-5.5.14-109.82.1 php5-exif-5.5.14-109.82.1 php5-exif-debuginfo-5.5.14-109.82.1 php5-fastcgi-5.5.14-109.82.1 php5-fastcgi-debuginfo-5.5.14-109.82.1 php5-fileinfo-5.5.14-109.82.1 php5-fileinfo-debuginfo-5.5.14-109.82.1 php5-fpm-5.5.14-109.82.1 php5-fpm-debuginfo-5.5.14-109.82.1 php5-ftp-5.5.14-109.82.1 php5-ftp-debuginfo-5.5.14-109.82.1 php5-gd-5.5.14-109.82.1 php5-gd-debuginfo-5.5.14-109.82.1 php5-gettext-5.5.14-109.82.1 php5-gettext-debuginfo-5.5.14-109.82.1 php5-gmp-5.5.14-109.82.1 php5-gmp-debuginfo-5.5.14-109.82.1 php5-iconv-5.5.14-109.82.1 php5-iconv-debuginfo-5.5.14-109.82.1 php5-imap-5.5.14-109.82.1 php5-imap-debuginfo-5.5.14-109.82.1 php5-intl-5.5.14-109.82.1 php5-intl-debuginfo-5.5.14-109.82.1 php5-json-5.5.14-109.82.1 php5-json-debuginfo-5.5.14-109.82.1 php5-ldap-5.5.14-109.82.1 php5-ldap-debuginfo-5.5.14-109.82.1 php5-mbstring-5.5.14-109.82.1 php5-mbstring-debuginfo-5.5.14-109.82.1 php5-mcrypt-5.5.14-109.82.1 php5-mcrypt-debuginfo-5.5.14-109.82.1 php5-mysql-5.5.14-109.82.1 php5-mysql-debuginfo-5.5.14-109.82.1 php5-odbc-5.5.14-109.82.1 php5-odbc-debuginfo-5.5.14-109.82.1 php5-opcache-5.5.14-109.82.1 php5-opcache-debuginfo-5.5.14-109.82.1 php5-openssl-5.5.14-109.82.1 php5-openssl-debuginfo-5.5.14-109.82.1 php5-pcntl-5.5.14-109.82.1 php5-pcntl-debuginfo-5.5.14-109.82.1 php5-pdo-5.5.14-109.82.1 php5-pdo-debuginfo-5.5.14-109.82.1 php5-pgsql-5.5.14-109.82.1 php5-pgsql-debuginfo-5.5.14-109.82.1 php5-phar-5.5.14-109.82.1 php5-phar-debuginfo-5.5.14-109.82.1 php5-posix-5.5.14-109.82.1 php5-posix-debuginfo-5.5.14-109.82.1 php5-pspell-5.5.14-109.82.1 php5-pspell-debuginfo-5.5.14-109.82.1 php5-shmop-5.5.14-109.82.1 php5-shmop-debuginfo-5.5.14-109.82.1 php5-snmp-5.5.14-109.82.1 php5-snmp-debuginfo-5.5.14-109.82.1 php5-soap-5.5.14-109.82.1 php5-soap-debuginfo-5.5.14-109.82.1 php5-sockets-5.5.14-109.82.1 php5-sockets-debuginfo-5.5.14-109.82.1 php5-sqlite-5.5.14-109.82.1 php5-sqlite-debuginfo-5.5.14-109.82.1 php5-suhosin-5.5.14-109.82.1 php5-suhosin-debuginfo-5.5.14-109.82.1 php5-sysvmsg-5.5.14-109.82.1 php5-sysvmsg-debuginfo-5.5.14-109.82.1 php5-sysvsem-5.5.14-109.82.1 php5-sysvsem-debuginfo-5.5.14-109.82.1 php5-sysvshm-5.5.14-109.82.1 php5-sysvshm-debuginfo-5.5.14-109.82.1 php5-tokenizer-5.5.14-109.82.1 php5-tokenizer-debuginfo-5.5.14-109.82.1 php5-wddx-5.5.14-109.82.1 php5-wddx-debuginfo-5.5.14-109.82.1 php5-xmlreader-5.5.14-109.82.1 php5-xmlreader-debuginfo-5.5.14-109.82.1 php5-xmlrpc-5.5.14-109.82.1 php5-xmlrpc-debuginfo-5.5.14-109.82.1 php5-xmlwriter-5.5.14-109.82.1 php5-xmlwriter-debuginfo-5.5.14-109.82.1 php5-xsl-5.5.14-109.82.1 php5-xsl-debuginfo-5.5.14-109.82.1 php5-zip-5.5.14-109.82.1 php5-zip-debuginfo-5.5.14-109.82.1 php5-zlib-5.5.14-109.82.1 php5-zlib-debuginfo-5.5.14-109.82.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php5-pear-5.5.14-109.82.1 References: https://www.suse.com/security/cve/CVE-2020-7070.html https://bugzilla.suse.com/1177352 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update for php7 addresses a critical vulnerability in session management, boosting your system's defense.. SUSE Security Update, PHP Fix, Cookie Overwrite Issue, Important Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 12, 2020 Important SuSE
100

SUSE: 2020:2477-1 Moderate: Php5 Use Of Freed Key Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php5 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2477-1 Rating: moderate References: #1175223 Cross-References: CVE-2020-7068 Affected Products: SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php5 fixes the following issues: - CVE-2020-7068: Use of freed hash key in the phar_parse_zipfile function (bsc#1175223). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-2477=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php5-5.5.14-109.79.1 apache2-mod_php5-debuginfo-5.5.14-109.79.1 php5-5.5.14-109.79.1 php5-bcmath-5.5.14-109.79.1 php5-bcmath-debuginfo-5.5.14-109.79.1 php5-bz2-5.5.14-109.79.1 php5-bz2-debuginfo-5.5.14-109.79.1 php5-calendar-5.5.14-109.79.1 php5-calendar-debuginfo-5.5.14-109.79.1 php5-ctype-5.5.14-109.79.1 php5-ctype-debuginfo-5.5.14-109.79.1 php5-curl-5.5.14-109.79.1 php5-curl-debuginfo-5.5.14-109.79.1 php5-dba-5.5.14-109.79.1 php5-dba-debuginfo-5.5.14-109.79.1 php5-debuginfo-5.5.14-109.79.1 php5-debugsource-5.5.14-109.79.1 php5-dom-5.5.14-109.79.1 php5-dom-debuginfo-5.5.14-109.79.1 php5-enchant-5.5.14-109.79.1 php5-enchant-debuginfo-5.5.14-109.79.1 php5-exif-5.5.14-109.79.1 php5-exif-debuginfo-5.5.14-109.79.1 php5-fastcgi-5.5.14-109.79.1 php5-fastcgi-debuginfo-5.5.14-109.79.1 php5-fileinfo-5.5.14-109.79.1 php5-fileinfo-debuginfo-5.5.14-109.79.1 php5-fpm-5.5.14-109.79.1 php5-fpm-debuginfo-5.5.14-109.79.1 php5-ftp-5.5.14-109.79.1 php5-ftp-debuginfo-5.5.14-109.79.1 php5-gd-5.5.14-109.79.1 php5-gd-debuginfo-5.5.14-109.79.1 php5-gettext-5.5.14-109.79.1 php5-gettext-debuginfo-5.5.14-109.79.1 php5-gmp-5.5.14-109.79.1 php5-gmp-debuginfo-5.5.14-109.79.1 php5-iconv-5.5.14-109.79.1 php5-iconv-debuginfo-5.5.14-109.79.1 php5-imap-5.5.14-109.79.1 php5-imap-debuginfo-5.5.14-109.79.1 php5-intl-5.5.14-109.79.1 php5-intl-debuginfo-5.5.14-109.79.1 php5-json-5.5.14-109.79.1 php5-json-debuginfo-5.5.14-109.79.1 php5-ldap-5.5.14-109.79.1 php5-ldap-debuginfo-5.5.14-109.79.1 php5-mbstring-5.5.14-109.79.1 php5-mbstring-debuginfo-5.5.14-109.79.1 php5-mcrypt-5.5.14-109.79.1 php5-mcrypt-debuginfo-5.5.14-109.79.1 php5-mysql-5.5.14-109.79.1 php5-mysql-debuginfo-5.5.14-109.79.1 php5-odbc-5.5.14-109.79.1 php5-odbc-debuginfo-5.5.14-109.79.1 php5-opcache-5.5.14-109.79.1 php5-opcache-debuginfo-5.5.14-109.79.1 php5-openssl-5.5.14-109.79.1 php5-openssl-debuginfo-5.5.14-109.79.1 php5-pcntl-5.5.14-109.79.1 php5-pcntl-debuginfo-5.5.14-109.79.1 php5-pdo-5.5.14-109.79.1 php5-pdo-debuginfo-5.5.14-109.79.1 php5-pgsql-5.5.14-109.79.1 php5-pgsql-debuginfo-5.5.14-109.79.1 php5-phar-5.5.14-109.79.1 php5-phar-debuginfo-5.5.14-109.79.1 php5-posix-5.5.14-109.79.1 php5-posix-debuginfo-5.5.14-109.79.1 php5-pspell-5.5.14-109.79.1 php5-pspell-debuginfo-5.5.14-109.79.1 php5-shmop-5.5.14-109.79.1 php5-shmop-debuginfo-5.5.14-109.79.1 php5-snmp-5.5.14-109.79.1 php5-snmp-debuginfo-5.5.14-109.79.1 php5-soap-5.5.14-109.79.1 php5-soap-debuginfo-5.5.14-109.79.1 php5-sockets-5.5.14-109.79.1 php5-sockets-debuginfo-5.5.14-109.79.1 php5-sqlite-5.5.14-109.79.1 php5-sqlite-debuginfo-5.5.14-109.79.1 php5-suhosin-5.5.14-109.79.1 php5-suhosin-debuginfo-5.5.14-109.79.1 php5-sysvmsg-5.5.14-109.79.1 php5-sysvmsg-debuginfo-5.5.14-109.79.1 php5-sysvsem-5.5.14-109.79.1 php5-sysvsem-debuginfo-5.5.14-109.79.1 php5-sysvshm-5.5.14-109.79.1 php5-sysvshm-debuginfo-5.5.14-109.79.1 php5-tokenizer-5.5.14-109.79.1 php5-tokenizer-debuginfo-5.5.14-109.79.1 php5-wddx-5.5.14-109.79.1 php5-wddx-debuginfo-5.5.14-109.79.1 php5-xmlreader-5.5.14-109.79.1 php5-xmlreader-debuginfo-5.5.14-109.79.1 php5-xmlrpc-5.5.14-109.79.1 php5-xmlrpc-debuginfo-5.5.14-109.79.1 php5-xmlwriter-5.5.14-109.79.1 php5-xmlwriter-debuginfo-5.5.14-109.79.1 php5-xsl-5.5.14-109.79.1 php5-xsl-debuginfo-5.5.14-109.79.1 php5-zip-5.5.14-109.79.1 php5-zip-debuginfo-5.5.14-109.79.1 php5-zlib-5.5.14-109.79.1 php5-zlib-debuginfo-5.5.14-109.79.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php5-pear-5.5.14-109.79.1 References: https://www.suse.com/security/cve/CVE-2020-7068.html https://bugzilla.suse.com/1175223 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has released a necessary security patch for php5 that mitigates CVE-2020-7068 risks and strengthens overall system integrity.. SUSE Security Update, php5 Threats, Web Scripting Issues. . LinuxSecurity.com Team

Calendar%202 Sep 03, 2020 SuSE
197

Debian 8: DLA-2261-1 Critical: php5 Disk Space Exploit Mitigation

It has been discovered, that a vulnerability in php5, a server-side, HTML-embedded scripting language, could lead to exhausted disk space on the server. When using overly long filenames or field names, a memory . Package : php5 Version : 5.6.40+dfsg-0+deb8u12 CVE ID : CVE-2019-11048 It has been discovered, that a vulnerability in php5, a server-side, HTML-embedded scripting language, could lead to exhausted disk space on the server. When using overly long filenames or field names, a memory limit could be hit which results in stopping the upload but not cleaning up behind. Further the embedded version of "file" is vulnerable to CVE-2019-18218. As it can not be exploited the same in php5 as in file, this issue is not handled as an own CVE but just as a bug, that has been fixed here (restrict the number of CDF_VECTOR elements to prevent a heap-based buffer overflow (4-byte out-of-bounds write)). For Debian 8 "Jessie", this problem has been fixed in version 5.6.40+dfsg-0+deb8u12. We recommend that you upgrade your php5 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance PHP5 to address CVE-2019-11048 and mitigate disk usage issues on Debian 8 for improved efficiency.. php5 Security Update,Debian LTS,CVE-2019-11048,Buffer Overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 29, 2020 Critical Debian LTS
197

Debian 8: DLA-2188-1 Moderate: Php5 Information Disclosure and Crashes

Three issues have been found in php5, a server-side, HTML-embedded scripting language. . Package : php5 Version : 5.6.40+dfsg-0+deb8u11 CVE ID : CVE-2020-7064 CVE-2020-7066 CVE-2020-7067 Three issues have been found in php5, a server-side, HTML-embedded scripting language. CVE-2020-7064 A one byte out-of-bounds read, which could potentially lead to information disclosure or crash. CVE-2020-7066 An URL containing zero (\0) character will be truncated at it, which may cause some software to make incorrect assumptions and possibly send some information to a wrong server. CVE-2020-7067 Using a malformed url-encoded string an Out-of-Bounds read can occur. For Debian 8 "Jessie", these problems have been fixed in version 5.6.40+dfsg-0+deb8u11. We recommend that you upgrade your php5 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . PHP version 5 has rolled out an update focusing on several security vulnerabilities, notably data exposure risks. Users should upgrade for improved system security and performance. Php5 Security Update, Debian LTS Advisory, Server-Side Scripting Fix, Information Disclosure. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 26, 2020 Important Debian LTS
197

Debian 8: DLA-2160-1 Moderate: PHP5 File Permission and Crash Issues

Two security issues have been identified and fixed in php5, a server-side, HTML-embedded scripting language. . Package : php5 Version : 5.6.40+dfsg-0+deb8u10 CVE ID : CVE-2020-7062 CVE-2020-7063 Two security issues have been identified and fixed in php5, a server-side, HTML-embedded scripting language. CVE-2020-7062 is about a possible null pointer derefernce, which would likely lead to a crash, during a failed upload with progress tracking. CVE-2020-7063 is about wrong file permissions of files added to tar with Phar::buildFromIterator when extracting them again. For Debian 8 "Jessie", these problems have been fixed in version 5.6.40+dfsg-0+deb8u10. We recommend that you upgrade your php5 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Security vulnerabilities patched in php5 5.6.40+dfsg-0+deb8u10 for Debian, addressing concerns related to directory access permissions and null reference errors.. Debian Security, PHP5 Update, Server Scripting, LTS Security Advisory. . LinuxSecurity.com Team

Calendar%202 Mar 26, 2020 Debian LTS
100

SUSE: 2020:0658-1 Moderate Security Vulnerabilities in php5 File Upload

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for php5 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0658-1 Rating: moderate References: #1165280 #1165289 Cross-References: CVE-2020-7062 CVE-2020-7063 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for php5 fixes the following issues: - CVE-2020-7062: Fixed a null pointer dereference when using file upload functionality under specific circumstances (bsc#1165280). - CVE-2020-7063: Fixed an issue where adding files change the permissions to default (bsc#1165289). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2020-658=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-658=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): php5-debuginfo-5.5.14-109.71.1 php5-debugsource-5.5.14-109.71.1 php5-devel-5.5.14-109.71.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php5-5.5.14-109.71.1 apache2-mod_php5-debuginfo-5.5.14-109.71.1 php5-5.5.14-109.71.1 php5-bcmath-5.5.14-109.71.1 php5-bcmath-debuginfo-5.5.14-109.71.1 php5-bz2-5.5.14-109.71.1 php5-bz2-debuginfo-5.5.14-109.71.1 php5-calendar-5.5.14-109.71.1 php5-calendar-debuginfo-5.5.14-109.71.1 php5-ctype-5.5.14-109.71.1 php5-ctype-debuginfo-5.5.14-109.71.1 php5-curl-5.5.14-109.71.1 php5-curl-debuginfo-5.5.14-109.71.1 php5-dba-5.5.14-109.71.1 php5-dba-debuginfo-5.5.14-109.71.1 php5-debuginfo-5.5.14-109.71.1 php5-debugsource-5.5.14-109.71.1 php5-dom-5.5.14-109.71.1 php5-dom-debuginfo-5.5.14-109.71.1 php5-enchant-5.5.14-109.71.1 php5-enchant-debuginfo-5.5.14-109.71.1 php5-exif-5.5.14-109.71.1 php5-exif-debuginfo-5.5.14-109.71.1 php5-fastcgi-5.5.14-109.71.1 php5-fastcgi-debuginfo-5.5.14-109.71.1 php5-fileinfo-5.5.14-109.71.1 php5-fileinfo-debuginfo-5.5.14-109.71.1 php5-fpm-5.5.14-109.71.1 php5-fpm-debuginfo-5.5.14-109.71.1 php5-ftp-5.5.14-109.71.1 php5-ftp-debuginfo-5.5.14-109.71.1 php5-gd-5.5.14-109.71.1 php5-gd-debuginfo-5.5.14-109.71.1 php5-gettext-5.5.14-109.71.1 php5-gettext-debuginfo-5.5.14-109.71.1 php5-gmp-5.5.14-109.71.1 php5-gmp-debuginfo-5.5.14-109.71.1 php5-iconv-5.5.14-109.71.1 php5-iconv-debuginfo-5.5.14-109.71.1 php5-imap-5.5.14-109.71.1 php5-imap-debuginfo-5.5.14-109.71.1 php5-intl-5.5.14-109.71.1 php5-intl-debuginfo-5.5.14-109.71.1 php5-json-5.5.14-109.71.1 php5-json-debuginfo-5.5.14-109.71.1 php5-ldap-5.5.14-109.71.1 php5-ldap-debuginfo-5.5.14-109.71.1 php5-mbstring-5.5.14-109.71.1 php5-mbstring-debuginfo-5.5.14-109.71.1 php5-mcrypt-5.5.14-109.71.1 php5-mcrypt-debuginfo-5.5.14-109.71.1 php5-mysql-5.5.14-109.71.1 php5-mysql-debuginfo-5.5.14-109.71.1 php5-odbc-5.5.14-109.71.1 php5-odbc-debuginfo-5.5.14-109.71.1 php5-opcache-5.5.14-109.71.1 php5-opcache-debuginfo-5.5.14-109.71.1 php5-openssl-5.5.14-109.71.1 php5-openssl-debuginfo-5.5.14-109.71.1 php5-pcntl-5.5.14-109.71.1 php5-pcntl-debuginfo-5.5.14-109.71.1 php5-pdo-5.5.14-109.71.1 php5-pdo-debuginfo-5.5.14-109.71.1 php5-pgsql-5.5.14-109.71.1 php5-pgsql-debuginfo-5.5.14-109.71.1 php5-phar-5.5.14-109.71.1 php5-phar-debuginfo-5.5.14-109.71.1 php5-posix-5.5.14-109.71.1 php5-posix-debuginfo-5.5.14-109.71.1 php5-pspell-5.5.14-109.71.1 php5-pspell-debuginfo-5.5.14-109.71.1 php5-shmop-5.5.14-109.71.1 php5-shmop-debuginfo-5.5.14-109.71.1 php5-snmp-5.5.14-109.71.1 php5-snmp-debuginfo-5.5.14-109.71.1 php5-soap-5.5.14-109.71.1 php5-soap-debuginfo-5.5.14-109.71.1 php5-sockets-5.5.14-109.71.1 php5-sockets-debuginfo-5.5.14-109.71.1 php5-sqlite-5.5.14-109.71.1 php5-sqlite-debuginfo-5.5.14-109.71.1 php5-suhosin-5.5.14-109.71.1 php5-suhosin-debuginfo-5.5.14-109.71.1 php5-sysvmsg-5.5.14-109.71.1 php5-sysvmsg-debuginfo-5.5.14-109.71.1 php5-sysvsem-5.5.14-109.71.1 php5-sysvsem-debuginfo-5.5.14-109.71.1 php5-sysvshm-5.5.14-109.71.1 php5-sysvshm-debuginfo-5.5.14-109.71.1 php5-tokenizer-5.5.14-109.71.1 php5-tokenizer-debuginfo-5.5.14-109.71.1 php5-wddx-5.5.14-109.71.1 php5-wddx-debuginfo-5.5.14-109.71.1 php5-xmlreader-5.5.14-109.71.1 php5-xmlreader-debuginfo-5.5.14-109.71.1 php5-xmlrpc-5.5.14-109.71.1 php5-xmlrpc-debuginfo-5.5.14-109.71.1 php5-xmlwriter-5.5.14-109.71.1 php5-xmlwriter-debuginfo-5.5.14-109.71.1 php5-xsl-5.5.14-109.71.1 php5-xsl-debuginfo-5.5.14-109.71.1 php5-zip-5.5.14-109.71.1 php5-zip-debuginfo-5.5.14-109.71.1 php5-zlib-5.5.14-109.71.1 php5-zlib-debuginfo-5.5.14-109.71.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php5-pear-5.5.14-109.71.1 References: https://www.suse.com/security/cve/CVE-2020-7062.html https://www.suse.com/security/cve/CVE-2020-7063.html https://bugzilla.suse.com/1165280 https://bugzilla.suse.com/1165289 _______________________________________________ sle-security-updates mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . The recent PHP5 update tackles two significant concerns: the security flaws related to file uploads and alterations in permission settings. Uncover the effective remedies implemented.. PHP Update, SUSE Security Update, Software Patch, Linux Security. . LinuxSecurity.com Team

Calendar%202 Mar 12, 2020 SuSE
197

Debian 8: DLA-2124-1 Critical: Php5 Information Disclosure

Two issues have been found in php5, a server-side, HTML-embedded scripting language. Both issues are related to crafted data that could lead to reading after an allocated buffer and result in information disclosure or . Package : php5 Version : 5.6.40+dfsg-0+deb8u9 CVE ID : CVE-2020-7059 CVE-2020-7060 Two issues have been found in php5, a server-side, HTML-embedded scripting language. Both issues are related to crafted data that could lead to reading after an allocated buffer and result in information disclosure or crash. For Debian 8 "Jessie", these problems have been fixed in version 5.6.40+dfsg-0+deb8u9. We recommend that you upgrade your php5 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS has issued a new update targeting vulnerabilities in php5, aimed at rectifying potential information leaks and system crashes.. Debian LTS, php5 update, security issues, server-side vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 28, 2020 Critical Debian LTS
100

SUSE: 2020:0522-1 Moderate: php5 Remote Code Execution and More

An update that solves 9 vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for php5 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0522-1 Rating: moderate References: #1145095 #1146360 #1154999 #1159922 #1159923 #1159924 #1159927 #1161982 #1162629 #1162632 Cross-References: CVE-2019-11041 CVE-2019-11042 CVE-2019-11043 CVE-2019-11045 CVE-2019-11046 CVE-2019-11047 CVE-2019-11050 CVE-2020-7059 CVE-2020-7060 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that solves 9 vulnerabilities and has one errata is now available. Description: This update for php5 fixes the following issues: Security issues fixed: - CVE-2019-11041: Fixed heap buffer over-read in exif_scan_thumbnail() (bsc#1146360). - CVE-2019-11042: Fixed heap buffer over-read in exif_process_user_comment() (bsc#1145095). - CVE-2019-11043: Fixed possible remote code execution via env_path_info underflow in fpm_main.c (bsc#1154999). - CVE-2019-11045: Fixed an issue with the PHP DirectoryIterator class that accepts filenames with embedded \0 bytes (bsc#1159923). - CVE-2019-11046: Fixed an out-of-bounds read in bc_shift_addsub (bsc#1159924). - CVE-2019-11047: Fixed an information disclosure in exif_read_data (bsc#1159922). - CVE-2019-11050: Fixed a buffer over-read in the EXIF extension (bsc#1159927). - CVE-2020-7059: Fixed an out-of-bounds read in php_strip_tags_ex (bsc#1162629). - CVE-2020-7060: Fixed a global buffer-overflow in mbfl_filt_conv_big5_wchar (bsc#1162632). Patch Instructions: To install this SUSE Security Update use theSUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2020-522=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-522=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): php5-debuginfo-5.5.14-109.68.1 php5-debugsource-5.5.14-109.68.1 php5-devel-5.5.14-109.68.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php5-5.5.14-109.68.1 apache2-mod_php5-debuginfo-5.5.14-109.68.1 php5-5.5.14-109.68.1 php5-bcmath-5.5.14-109.68.1 php5-bcmath-debuginfo-5.5.14-109.68.1 php5-bz2-5.5.14-109.68.1 php5-bz2-debuginfo-5.5.14-109.68.1 php5-calendar-5.5.14-109.68.1 php5-calendar-debuginfo-5.5.14-109.68.1 php5-ctype-5.5.14-109.68.1 php5-ctype-debuginfo-5.5.14-109.68.1 php5-curl-5.5.14-109.68.1 php5-curl-debuginfo-5.5.14-109.68.1 php5-dba-5.5.14-109.68.1 php5-dba-debuginfo-5.5.14-109.68.1 php5-debuginfo-5.5.14-109.68.1 php5-debugsource-5.5.14-109.68.1 php5-dom-5.5.14-109.68.1 php5-dom-debuginfo-5.5.14-109.68.1 php5-enchant-5.5.14-109.68.1 php5-enchant-debuginfo-5.5.14-109.68.1 php5-exif-5.5.14-109.68.1 php5-exif-debuginfo-5.5.14-109.68.1 php5-fastcgi-5.5.14-109.68.1 php5-fastcgi-debuginfo-5.5.14-109.68.1 php5-fileinfo-5.5.14-109.68.1 php5-fileinfo-debuginfo-5.5.14-109.68.1 php5-fpm-5.5.14-109.68.1 php5-fpm-debuginfo-5.5.14-109.68.1 php5-ftp-5.5.14-109.68.1 php5-ftp-debuginfo-5.5.14-109.68.1 php5-gd-5.5.14-109.68.1 php5-gd-debuginfo-5.5.14-109.68.1 php5-gettext-5.5.14-109.68.1 php5-gettext-debuginfo-5.5.14-109.68.1 php5-gmp-5.5.14-109.68.1 php5-gmp-debuginfo-5.5.14-109.68.1 php5-iconv-5.5.14-109.68.1 php5-iconv-debuginfo-5.5.14-109.68.1 php5-imap-5.5.14-109.68.1 php5-imap-debuginfo-5.5.14-109.68.1 php5-intl-5.5.14-109.68.1 php5-intl-debuginfo-5.5.14-109.68.1 php5-json-5.5.14-109.68.1 php5-json-debuginfo-5.5.14-109.68.1 php5-ldap-5.5.14-109.68.1 php5-ldap-debuginfo-5.5.14-109.68.1 php5-mbstring-5.5.14-109.68.1 php5-mbstring-debuginfo-5.5.14-109.68.1 php5-mcrypt-5.5.14-109.68.1 php5-mcrypt-debuginfo-5.5.14-109.68.1 php5-mysql-5.5.14-109.68.1 php5-mysql-debuginfo-5.5.14-109.68.1 php5-odbc-5.5.14-109.68.1 php5-odbc-debuginfo-5.5.14-109.68.1 php5-opcache-5.5.14-109.68.1 php5-opcache-debuginfo-5.5.14-109.68.1 php5-openssl-5.5.14-109.68.1 php5-openssl-debuginfo-5.5.14-109.68.1 php5-pcntl-5.5.14-109.68.1 php5-pcntl-debuginfo-5.5.14-109.68.1 php5-pdo-5.5.14-109.68.1 php5-pdo-debuginfo-5.5.14-109.68.1 php5-pgsql-5.5.14-109.68.1 php5-pgsql-debuginfo-5.5.14-109.68.1 php5-phar-5.5.14-109.68.1 php5-phar-debuginfo-5.5.14-109.68.1 php5-posix-5.5.14-109.68.1 php5-posix-debuginfo-5.5.14-109.68.1 php5-pspell-5.5.14-109.68.1 php5-pspell-debuginfo-5.5.14-109.68.1 php5-shmop-5.5.14-109.68.1 php5-shmop-debuginfo-5.5.14-109.68.1 php5-snmp-5.5.14-109.68.1 php5-snmp-debuginfo-5.5.14-109.68.1 php5-soap-5.5.14-109.68.1 php5-soap-debuginfo-5.5.14-109.68.1 php5-sockets-5.5.14-109.68.1 php5-sockets-debuginfo-5.5.14-109.68.1 php5-sqlite-5.5.14-109.68.1 php5-sqlite-debuginfo-5.5.14-109.68.1 php5-suhosin-5.5.14-109.68.1 php5-suhosin-debuginfo-5.5.14-109.68.1 php5-sysvmsg-5.5.14-109.68.1 php5-sysvmsg-debuginfo-5.5.14-109.68.1 php5-sysvsem-5.5.14-109.68.1 php5-sysvsem-debuginfo-5.5.14-109.68.1 php5-sysvshm-5.5.14-109.68.1 php5-sysvshm-debuginfo-5.5.14-109.68.1 php5-tokenizer-5.5.14-109.68.1 php5-tokenizer-debuginfo-5.5.14-109.68.1 php5-wddx-5.5.14-109.68.1 php5-wddx-debuginfo-5.5.14-109.68.1 php5-xmlreader-5.5.14-109.68.1 php5-xmlreader-debuginfo-5.5.14-109.68.1 php5-xmlrpc-5.5.14-109.68.1 php5-xmlrpc-debuginfo-5.5.14-109.68.1 php5-xmlwriter-5.5.14-109.68.1 php5-xmlwriter-debuginfo-5.5.14-109.68.1 php5-xsl-5.5.14-109.68.1 php5-xsl-debuginfo-5.5.14-109.68.1 php5-zip-5.5.14-109.68.1 php5-zip-debuginfo-5.5.14-109.68.1 php5-zlib-5.5.14-109.68.1 php5-zlib-debuginfo-5.5.14-109.68.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php5-pear-5.5.14-109.68.1 References: https://www.suse.com/security/cve/CVE-2019-11041.html https://www.suse.com/security/cve/CVE-2019-11042.html https://www.suse.com/security/cve/CVE-2019-11043.html https://www.suse.com/security/cve/CVE-2019-11045.html https://www.suse.com/security/cve/CVE-2019-11046.html https://www.suse.com/security/cve/CVE-2019-11047.html https://www.suse.com/security/cve/CVE-2019-11050.html https://www.suse.com/security/cve/CVE-2020-7059.html https://www.suse.com/security/cve/CVE-2020-7060.html https://bugzilla.suse.com/1145095 https://bugzilla.suse.com/1146360 https://bugzilla.suse.com/1154999 https://bugzilla.suse.com/1159922 https://bugzilla.suse.com/1159923 https://bugzilla.suse.com/1159924 https://bugzilla.suse.com/1159927 https://bugzilla.suse.com/1161982 https://bugzilla.suse.com/1162629 https://bugzilla.suse.com/1162632 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . The latest php5 update fixes serious security issues, addressing remote code execution threats alongside other concerns. Check the official announcement for full details. php5 Security Patch, SUSE Update,Remote Code Execution Fix, Moderate Security Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 28, 2020 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200