Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:14668-1 Rating: important References: #1182049 Cross-References: CVE-2021-21702 CVSS scores: CVE-2021-21702 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-21702 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php53 fixes the following issues: - CVE-2021-21702 [bsc#1182049]: NULL pointer dereference in SoapClient Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-php53-14668=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-php53-14668=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-14668=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-php53-14668=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-112.99.2 php53-5.3.17-112.99.2 php53-bcmath-5.3.17-112.99.2 php53-bz2-5.3.17-112.99.2 php53-calendar-5.3.17-112.99.2 php53-ctype-5.3.17-112.99.2 php53-curl-5.3.17-112.99.2 php53-dba-5.3.17-112.99.2 php53-dom-5.3.17-112.99.2 php53-exif-5.3.17-112.99.2 php53-fastcgi-5.3.17-112.99.2 php53-fileinfo-5.3.17-112.99.2 php53-ftp-5.3.17-112.99.2 php53-gd-5.3.17-112.99.2 php53-gettext-5.3.17-112.99.2 php53-gmp-5.3.17-112.99.2 php53-iconv-5.3.17-112.99.2 php53-intl-5.3.17-112.99.2 php53-json-5.3.17-112.99.2 php53-ldap-5.3.17-112.99.2 php53-mbstring-5.3.17-112.99.2 php53-mcrypt-5.3.17-112.99.2 php53-mysql-5.3.17-112.99.2 php53-odbc-5.3.17-112.99.2 php53-openssl-5.3.17-112.99.2 php53-pcntl-5.3.17-112.99.2 php53-pdo-5.3.17-112.99.2 php53-pear-5.3.17-112.99.2 php53-pgsql-5.3.17-112.99.2 php53-pspell-5.3.17-112.99.2 php53-shmop-5.3.17-112.99.2 php53-snmp-5.3.17-112.99.2 php53-soap-5.3.17-112.99.2 php53-suhosin-5.3.17-112.99.2 php53-sysvmsg-5.3.17-112.99.2 php53-sysvsem-5.3.17-112.99.2 php53-sysvshm-5.3.17-112.99.2 php53-tokenizer-5.3.17-112.99.2 php53-wddx-5.3.17-112.99.2 php53-xmlreader-5.3.17-112.99.2 php53-xmlrpc-5.3.17-112.99.2 php53-xmlwriter-5.3.17-112.99.2 php53-xsl-5.3.17-112.99.2 php53-zip-5.3.17-112.99.2 php53-zlib-5.3.17-112.99.2 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): apache2-mod_php53-5.3.17-112.99.2 php53-5.3.17-112.99.2 php53-bcmath-5.3.17-112.99.2 php53-bz2-5.3.17-112.99.2 php53-calendar-5.3.17-112.99.2 php53-ctype-5.3.17-112.99.2 php53-curl-5.3.17-112.99.2 php53-dba-5.3.17-112.99.2 php53-dom-5.3.17-112.99.2 php53-exif-5.3.17-112.99.2 php53-fastcgi-5.3.17-112.99.2 php53-fileinfo-5.3.17-112.99.2 php53-ftp-5.3.17-112.99.2 php53-gd-5.3.17-112.99.2 php53-gettext-5.3.17-112.99.2 php53-gmp-5.3.17-112.99.2 php53-iconv-5.3.17-112.99.2 php53-intl-5.3.17-112.99.2 php53-json-5.3.17-112.99.2 php53-ldap-5.3.17-112.99.2 php53-mbstring-5.3.17-112.99.2 php53-mcrypt-5.3.17-112.99.2 php53-mysql-5.3.17-112.99.2 php53-odbc-5.3.17-112.99.2 php53-openssl-5.3.17-112.99.2 php53-pcntl-5.3.17-112.99.2 php53-pdo-5.3.17-112.99.2 php53-pear-5.3.17-112.99.2 php53-pgsql-5.3.17-112.99.2 php53-pspell-5.3.17-112.99.2 php53-shmop-5.3.17-112.99.2 php53-snmp-5.3.17-112.99.2 php53-soap-5.3.17-112.99.2 php53-suhosin-5.3.17-112.99.2 php53-sysvmsg-5.3.17-112.99.2 php53-sysvsem-5.3.17-112.99.2 php53-sysvshm-5.3.17-112.99.2 php53-tokenizer-5.3.17-112.99.2 php53-wddx-5.3.17-112.99.2 php53-xmlreader-5.3.17-112.99.2 php53-xmlrpc-5.3.17-112.99.2 php53-xmlwriter-5.3.17-112.99.2 php53-xsl-5.3.17-112.99.2 php53-zip-5.3.17-112.99.2 php53-zlib-5.3.17-112.99.2 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): php53-debuginfo-5.3.17-112.99.2 php53-debugsource-5.3.17-112.99.2 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): php53-debuginfo-5.3.17-112.99.2 php53-debugsource-5.3.17-112.99.2 References: https://www.suse.com/security/cve/CVE-2021-21702.html https://bugzilla.suse.com/1182049 . A recent security patch for php53 mitigates risks associated with NULL pointer dereference vulnerabilities in SoapClient. Critical update now accessible for SUSE Linux subscribers.. SUSE Linux, php security, important update, NULL pointer, software patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes 6 vulnerabilities is now available. . SUSE Security Update: Security update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14289-1 Rating: moderate References: #1159922 #1159923 #1159924 #1159927 #1161982 #1162629 Cross-References: CVE-2019-11045 CVE-2019-11046 CVE-2019-11047 CVE-2019-11050 CVE-2019-20433 CVE-2020-7059 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for php53 fixes the following issues: Security issues fixed: - CVE-2020-7059: Fixed an out-of-bounds read in php_strip_tags_ex (bsc#1162629). - CVE-2019-11045: Fixed an issue with the PHP DirectoryIterator class that accepts filenames with embedded \0 bytes (bsc#1159923). - CVE-2019-11046: Fixed an out-of-bounds read in bc_shift_addsub (bsc#1159924). - CVE-2019-11047: Fixed an information disclosure in exif_read_data (bsc#1159922). - CVE-2019-11050: Fixed a buffer over-read in the EXIF extension (bsc#1159927). - CVE-2019-20433: Fixed a buffer over-read when processing strings ending with a single '\0' byte with ucs-2 and ucs-4 encoding (bsc#1161982). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-php53-14289=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patchsleposp3-php53-14289=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-14289=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-php53-14289=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-112.79.1 php53-5.3.17-112.79.1 php53-bcmath-5.3.17-112.79.1 php53-bz2-5.3.17-112.79.1 php53-calendar-5.3.17-112.79.1 php53-ctype-5.3.17-112.79.1 php53-curl-5.3.17-112.79.1 php53-dba-5.3.17-112.79.1 php53-dom-5.3.17-112.79.1 php53-exif-5.3.17-112.79.1 php53-fastcgi-5.3.17-112.79.1 php53-fileinfo-5.3.17-112.79.1 php53-ftp-5.3.17-112.79.1 php53-gd-5.3.17-112.79.1 php53-gettext-5.3.17-112.79.1 php53-gmp-5.3.17-112.79.1 php53-iconv-5.3.17-112.79.1 php53-intl-5.3.17-112.79.1 php53-json-5.3.17-112.79.1 php53-ldap-5.3.17-112.79.1 php53-mbstring-5.3.17-112.79.1 php53-mcrypt-5.3.17-112.79.1 php53-mysql-5.3.17-112.79.1 php53-odbc-5.3.17-112.79.1 php53-openssl-5.3.17-112.79.1 php53-pcntl-5.3.17-112.79.1 php53-pdo-5.3.17-112.79.1 php53-pear-5.3.17-112.79.1 php53-pgsql-5.3.17-112.79.1 php53-pspell-5.3.17-112.79.1 php53-shmop-5.3.17-112.79.1 php53-snmp-5.3.17-112.79.1 php53-soap-5.3.17-112.79.1 php53-suhosin-5.3.17-112.79.1 php53-sysvmsg-5.3.17-112.79.1 php53-sysvsem-5.3.17-112.79.1 php53-sysvshm-5.3.17-112.79.1 php53-tokenizer-5.3.17-112.79.1 php53-wddx-5.3.17-112.79.1 php53-xmlreader-5.3.17-112.79.1 php53-xmlrpc-5.3.17-112.79.1 php53-xmlwriter-5.3.17-112.79.1 php53-xsl-5.3.17-112.79.1 php53-zip-5.3.17-112.79.1 php53-zlib-5.3.17-112.79.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): apache2-mod_php53-5.3.17-112.79.1 php53-5.3.17-112.79.1 php53-bcmath-5.3.17-112.79.1 php53-bz2-5.3.17-112.79.1 php53-calendar-5.3.17-112.79.1 php53-ctype-5.3.17-112.79.1 php53-curl-5.3.17-112.79.1 php53-dba-5.3.17-112.79.1 php53-dom-5.3.17-112.79.1 php53-exif-5.3.17-112.79.1 php53-fastcgi-5.3.17-112.79.1 php53-fileinfo-5.3.17-112.79.1 php53-ftp-5.3.17-112.79.1 php53-gd-5.3.17-112.79.1 php53-gettext-5.3.17-112.79.1 php53-gmp-5.3.17-112.79.1 php53-iconv-5.3.17-112.79.1 php53-intl-5.3.17-112.79.1 php53-json-5.3.17-112.79.1 php53-ldap-5.3.17-112.79.1 php53-mbstring-5.3.17-112.79.1 php53-mcrypt-5.3.17-112.79.1 php53-mysql-5.3.17-112.79.1 php53-odbc-5.3.17-112.79.1 php53-openssl-5.3.17-112.79.1 php53-pcntl-5.3.17-112.79.1 php53-pdo-5.3.17-112.79.1 php53-pear-5.3.17-112.79.1 php53-pgsql-5.3.17-112.79.1 php53-pspell-5.3.17-112.79.1 php53-shmop-5.3.17-112.79.1 php53-snmp-5.3.17-112.79.1 php53-soap-5.3.17-112.79.1 php53-suhosin-5.3.17-112.79.1 php53-sysvmsg-5.3.17-112.79.1 php53-sysvsem-5.3.17-112.79.1 php53-sysvshm-5.3.17-112.79.1 php53-tokenizer-5.3.17-112.79.1 php53-wddx-5.3.17-112.79.1 php53-xmlreader-5.3.17-112.79.1 php53-xmlrpc-5.3.17-112.79.1 php53-xmlwriter-5.3.17-112.79.1 php53-xsl-5.3.17-112.79.1 php53-zip-5.3.17-112.79.1 php53-zlib-5.3.17-112.79.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): php53-debuginfo-5.3.17-112.79.1 php53-debugsource-5.3.17-112.79.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): php53-debuginfo-5.3.17-112.79.1 php53-debugsource-5.3.17-112.79.1 References: https://www.suse.com/security/cve/CVE-2019-11045.html https://www.suse.com/security/cve/CVE-2019-11046.html https://www.suse.com/security/cve/CVE-2019-11047.html https://www.suse.com/security/cve/CVE-2019-11050.html https://www.suse.com/security/cve/CVE-2019-20433.html https://www.suse.com/security/cve/CVE-2020-7059.html https://bugzilla.suse.com/1159922 https://bugzilla.suse.com/1159923 https://bugzilla.suse.com/1159924 https://bugzilla.suse.com/1159927 https://bugzilla.suse.com/1161982 https://bugzilla.suse.com/1162629 _______________________________________________ sle-security-updates mailing list
An update that fixes 11 vulnerabilities is now available. . SUSE Security Update: Security update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:14013-1 Rating: moderate References: #1126711 #1126713 #1126821 #1126823 #1127122 #1128722 #1128883 #1128886 #1128887 #1128889 #1128892 Cross-References: CVE-2018-20783 CVE-2019-9020 CVE-2019-9021 CVE-2019-9023 CVE-2019-9024 CVE-2019-9637 CVE-2019-9638 CVE-2019-9639 CVE-2019-9640 CVE-2019-9641 CVE-2019-9675 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes 11 vulnerabilities is now available. Description: This update for php53 fixes the following issues: Security issues fixed: - CVE-2019-9637: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128892). - CVE-2019-9675: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128886). - CVE-2019-9638: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension ((bsc#1128889). - CVE-2019-9639: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128887). - CVE-2019-9640: Fixed improper implementation of rename function and multiple invalid memory access in EXIF extension (bsc#1128883). - CVE-2019-9024: Fixed a vulnerability in xmlrpc_decode function which could allow to a hostile XMLRPC server to cause memory read outside the allocatedareas (bsc#1126821). - CVE-2019-9020: Fixed a heap out of bounds in xmlrpc_decode function (bsc#1126711). - CVE-2018-20783: Fixed a buffer over-read in PHAR reading functions which could allow an attacker to read allocated and unallocated memory when parsing a phar file (bsc#1127122). - CVE-2019-9021: Fixed a heap buffer-based buffer over-read in PHAR reading functions which could allow an attacker to read allocated and unallocated memory when parsing a phar file (bsc#1126713). - CVE-2019-9023: Fixed multiple heap-based buffer over-read instances in mbstring regular expression functions (bsc#1126823). - CVE-2019-9641: Fixed multiple invalid memory access in EXIF extension and improved insecure implementation of rename function (bsc#1128722). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-php53-14013=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-php53-14013=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-php53-14013=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-14013=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-devel-5.3.17-112.58.1 php53-imap-5.3.17-112.58.1 php53-posix-5.3.17-112.58.1 php53-readline-5.3.17-112.58.1 php53-sockets-5.3.17-112.58.1 php53-sqlite-5.3.17-112.58.1 php53-tidy-5.3.17-112.58.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-112.58.1 php53-5.3.17-112.58.1 php53-bcmath-5.3.17-112.58.1 php53-bz2-5.3.17-112.58.1 php53-calendar-5.3.17-112.58.1 php53-ctype-5.3.17-112.58.1 php53-curl-5.3.17-112.58.1 php53-dba-5.3.17-112.58.1 php53-dom-5.3.17-112.58.1 php53-exif-5.3.17-112.58.1 php53-fastcgi-5.3.17-112.58.1 php53-fileinfo-5.3.17-112.58.1 php53-ftp-5.3.17-112.58.1 php53-gd-5.3.17-112.58.1 php53-gettext-5.3.17-112.58.1 php53-gmp-5.3.17-112.58.1 php53-iconv-5.3.17-112.58.1 php53-intl-5.3.17-112.58.1 php53-json-5.3.17-112.58.1 php53-ldap-5.3.17-112.58.1 php53-mbstring-5.3.17-112.58.1 php53-mcrypt-5.3.17-112.58.1 php53-mysql-5.3.17-112.58.1 php53-odbc-5.3.17-112.58.1 php53-openssl-5.3.17-112.58.1 php53-pcntl-5.3.17-112.58.1 php53-pdo-5.3.17-112.58.1 php53-pear-5.3.17-112.58.1 php53-pgsql-5.3.17-112.58.1 php53-pspell-5.3.17-112.58.1 php53-shmop-5.3.17-112.58.1 php53-snmp-5.3.17-112.58.1 php53-soap-5.3.17-112.58.1 php53-suhosin-5.3.17-112.58.1 php53-sysvmsg-5.3.17-112.58.1 php53-sysvsem-5.3.17-112.58.1 php53-sysvshm-5.3.17-112.58.1 php53-tokenizer-5.3.17-112.58.1 php53-wddx-5.3.17-112.58.1 php53-xmlreader-5.3.17-112.58.1 php53-xmlrpc-5.3.17-112.58.1 php53-xmlwriter-5.3.17-112.58.1 php53-xsl-5.3.17-112.58.1 php53-zip-5.3.17-112.58.1 php53-zlib-5.3.17-112.58.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): apache2-mod_php53-5.3.17-112.58.1 php53-5.3.17-112.58.1 php53-bcmath-5.3.17-112.58.1 php53-bz2-5.3.17-112.58.1 php53-calendar-5.3.17-112.58.1 php53-ctype-5.3.17-112.58.1 php53-curl-5.3.17-112.58.1 php53-dba-5.3.17-112.58.1 php53-dom-5.3.17-112.58.1 php53-exif-5.3.17-112.58.1 php53-fastcgi-5.3.17-112.58.1 php53-fileinfo-5.3.17-112.58.1 php53-ftp-5.3.17-112.58.1 php53-gd-5.3.17-112.58.1 php53-gettext-5.3.17-112.58.1 php53-gmp-5.3.17-112.58.1 php53-iconv-5.3.17-112.58.1 php53-intl-5.3.17-112.58.1 php53-json-5.3.17-112.58.1 php53-ldap-5.3.17-112.58.1 php53-mbstring-5.3.17-112.58.1 php53-mcrypt-5.3.17-112.58.1 php53-mysql-5.3.17-112.58.1 php53-odbc-5.3.17-112.58.1 php53-openssl-5.3.17-112.58.1 php53-pcntl-5.3.17-112.58.1 php53-pdo-5.3.17-112.58.1 php53-pear-5.3.17-112.58.1 php53-pgsql-5.3.17-112.58.1 php53-pspell-5.3.17-112.58.1 php53-shmop-5.3.17-112.58.1 php53-snmp-5.3.17-112.58.1 php53-soap-5.3.17-112.58.1 php53-suhosin-5.3.17-112.58.1 php53-sysvmsg-5.3.17-112.58.1 php53-sysvsem-5.3.17-112.58.1 php53-sysvshm-5.3.17-112.58.1 php53-tokenizer-5.3.17-112.58.1 php53-wddx-5.3.17-112.58.1 php53-xmlreader-5.3.17-112.58.1 php53-xmlrpc-5.3.17-112.58.1 php53-xmlwriter-5.3.17-112.58.1 php53-xsl-5.3.17-112.58.1 php53-zip-5.3.17-112.58.1 php53-zlib-5.3.17-112.58.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-debuginfo-5.3.17-112.58.1 php53-debugsource-5.3.17-112.58.1 References: https://www.suse.com/security/cve/CVE-2018-20783.html https://www.suse.com/security/cve/CVE-2019-9020.html https://www.suse.com/security/cve/CVE-2019-9021.html https://www.suse.com/security/cve/CVE-2019-9023.html https://www.suse.com/security/cve/CVE-2019-9024.html https://www.suse.com/security/cve/CVE-2019-9637.html https://www.suse.com/security/cve/CVE-2019-9638.html https://www.suse.com/security/cve/CVE-2019-9639.html https://www.suse.com/security/cve/CVE-2019-9640.html https://www.suse.com/security/cve/CVE-2019-9641.html https://www.suse.com/security/cve/CVE-2019-9675.html https://bugzilla.suse.com/1126711 https://bugzilla.suse.com/1126713 https://bugzilla.suse.com/1126821 https://bugzilla.suse.com/1126823 https://bugzilla.suse.com/1127122 https://bugzilla.suse.com/1128722 https://bugzilla.suse.com/1128883 https://bugzilla.suse.com/1128886 https://bugzilla.suse.com/1128887 https://bugzilla.suse.com/1128889 https://bugzilla.suse.com/1128892 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Recommended update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3986-1 Rating: moderate References: #1117107 Cross-References: CVE-2018-19518 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php53 fixes the following issues: Security issue fixed: - CVE-2018-19518: Fixed imap_open script injection flaw (bsc#1117107). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-php53-13893=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-php53-13893=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-13893=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-devel-5.3.17-112.45.1 php53-imap-5.3.17-112.45.1 php53-posix-5.3.17-112.45.1 php53-readline-5.3.17-112.45.1 php53-sockets-5.3.17-112.45.1 php53-sqlite-5.3.17-112.45.1 php53-tidy-5.3.17-112.45.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-112.45.1 php53-5.3.17-112.45.1 php53-bcmath-5.3.17-112.45.1 php53-bz2-5.3.17-112.45.1 php53-calendar-5.3.17-112.45.1 php53-ctype-5.3.17-112.45.1 php53-curl-5.3.17-112.45.1 php53-dba-5.3.17-112.45.1 php53-dom-5.3.17-112.45.1 php53-exif-5.3.17-112.45.1 php53-fastcgi-5.3.17-112.45.1 php53-fileinfo-5.3.17-112.45.1 php53-ftp-5.3.17-112.45.1 php53-gd-5.3.17-112.45.1 php53-gettext-5.3.17-112.45.1 php53-gmp-5.3.17-112.45.1 php53-iconv-5.3.17-112.45.1 php53-intl-5.3.17-112.45.1 php53-json-5.3.17-112.45.1 php53-ldap-5.3.17-112.45.1 php53-mbstring-5.3.17-112.45.1 php53-mcrypt-5.3.17-112.45.1 php53-mysql-5.3.17-112.45.1 php53-odbc-5.3.17-112.45.1 php53-openssl-5.3.17-112.45.1 php53-pcntl-5.3.17-112.45.1 php53-pdo-5.3.17-112.45.1 php53-pear-5.3.17-112.45.1 php53-pgsql-5.3.17-112.45.1 php53-pspell-5.3.17-112.45.1 php53-shmop-5.3.17-112.45.1 php53-snmp-5.3.17-112.45.1 php53-soap-5.3.17-112.45.1 php53-suhosin-5.3.17-112.45.1 php53-sysvmsg-5.3.17-112.45.1 php53-sysvsem-5.3.17-112.45.1 php53-sysvshm-5.3.17-112.45.1 php53-tokenizer-5.3.17-112.45.1 php53-wddx-5.3.17-112.45.1 php53-xmlreader-5.3.17-112.45.1 php53-xmlrpc-5.3.17-112.45.1 php53-xmlwriter-5.3.17-112.45.1 php53-xsl-5.3.17-112.45.1 php53-zip-5.3.17-112.45.1 php53-zlib-5.3.17-112.45.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-debuginfo-5.3.17-112.45.1 php53-debugsource-5.3.17-112.45.1 References: https://www.suse.com/security/cve/CVE-2018-19518.html https://bugzilla.suse.com/1117107 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3018-1 Rating: moderate References: #1108753 Cross-References: CVE-2018-17082 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php53 fixes the following issue: - CVE-2018-17082: The Apache2 component in PHP allowed XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade was mishandled in the php_handler function (bsc#1108753) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-php53-13807=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-php53-13807=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-13807=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-devel-5.3.17-112.41.1 php53-imap-5.3.17-112.41.1 php53-posix-5.3.17-112.41.1 php53-readline-5.3.17-112.41.1 php53-sockets-5.3.17-112.41.1 php53-sqlite-5.3.17-112.41.1 php53-tidy-5.3.17-112.41.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-112.41.1 php53-5.3.17-112.41.1 php53-bcmath-5.3.17-112.41.1 php53-bz2-5.3.17-112.41.1 php53-calendar-5.3.17-112.41.1 php53-ctype-5.3.17-112.41.1 php53-curl-5.3.17-112.41.1 php53-dba-5.3.17-112.41.1 php53-dom-5.3.17-112.41.1 php53-exif-5.3.17-112.41.1 php53-fastcgi-5.3.17-112.41.1 php53-fileinfo-5.3.17-112.41.1 php53-ftp-5.3.17-112.41.1 php53-gd-5.3.17-112.41.1 php53-gettext-5.3.17-112.41.1 php53-gmp-5.3.17-112.41.1 php53-iconv-5.3.17-112.41.1 php53-intl-5.3.17-112.41.1 php53-json-5.3.17-112.41.1 php53-ldap-5.3.17-112.41.1 php53-mbstring-5.3.17-112.41.1 php53-mcrypt-5.3.17-112.41.1 php53-mysql-5.3.17-112.41.1 php53-odbc-5.3.17-112.41.1 php53-openssl-5.3.17-112.41.1 php53-pcntl-5.3.17-112.41.1 php53-pdo-5.3.17-112.41.1 php53-pear-5.3.17-112.41.1 php53-pgsql-5.3.17-112.41.1 php53-pspell-5.3.17-112.41.1 php53-shmop-5.3.17-112.41.1 php53-snmp-5.3.17-112.41.1 php53-soap-5.3.17-112.41.1 php53-suhosin-5.3.17-112.41.1 php53-sysvmsg-5.3.17-112.41.1 php53-sysvsem-5.3.17-112.41.1 php53-sysvshm-5.3.17-112.41.1 php53-tokenizer-5.3.17-112.41.1 php53-wddx-5.3.17-112.41.1 php53-xmlreader-5.3.17-112.41.1 php53-xmlrpc-5.3.17-112.41.1 php53-xmlwriter-5.3.17-112.41.1 php53-xsl-5.3.17-112.41.1 php53-zip-5.3.17-112.41.1 php53-zlib-5.3.17-112.41.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-debuginfo-5.3.17-112.41.1 php53-debugsource-5.3.17-112.41.1 References: https://www.suse.com/security/cve/CVE-2018-17082.html https://bugzilla.suse.com/1108753 _______________________________________________ sle-security-updates mailing list
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2044-1 Rating: moderate References: #1096984 #1099098 Cross-References: CVE-2018-10360 CVE-2018-12882 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for php53 fixes the following issues: The following security issue was fixed: - An out-of-bounds read in the do_core_note function in readelf.c in libmagic.a allowed remote attackers to cause a denial of service via a crafted ELF file (CVE-2018-10360, bsc#1096984) - CVE-2018-12882: exif_read_from_impl allowed attackers to trigger a use-after-free (in exif_read_from_file) because it closed a stream that it is not responsible for closing (bsc#1099098) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-php53-13700=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-php53-13700=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-13700=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-devel-5.3.17-112.28.1 php53-imap-5.3.17-112.28.1 php53-posix-5.3.17-112.28.1 php53-readline-5.3.17-112.28.1 php53-sockets-5.3.17-112.28.1 php53-sqlite-5.3.17-112.28.1 php53-tidy-5.3.17-112.28.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-112.28.1 php53-5.3.17-112.28.1 php53-bcmath-5.3.17-112.28.1 php53-bz2-5.3.17-112.28.1 php53-calendar-5.3.17-112.28.1 php53-ctype-5.3.17-112.28.1 php53-curl-5.3.17-112.28.1 php53-dba-5.3.17-112.28.1 php53-dom-5.3.17-112.28.1 php53-exif-5.3.17-112.28.1 php53-fastcgi-5.3.17-112.28.1 php53-fileinfo-5.3.17-112.28.1 php53-ftp-5.3.17-112.28.1 php53-gd-5.3.17-112.28.1 php53-gettext-5.3.17-112.28.1 php53-gmp-5.3.17-112.28.1 php53-iconv-5.3.17-112.28.1 php53-intl-5.3.17-112.28.1 php53-json-5.3.17-112.28.1 php53-ldap-5.3.17-112.28.1 php53-mbstring-5.3.17-112.28.1 php53-mcrypt-5.3.17-112.28.1 php53-mysql-5.3.17-112.28.1 php53-odbc-5.3.17-112.28.1 php53-openssl-5.3.17-112.28.1 php53-pcntl-5.3.17-112.28.1 php53-pdo-5.3.17-112.28.1 php53-pear-5.3.17-112.28.1 php53-pgsql-5.3.17-112.28.1 php53-pspell-5.3.17-112.28.1 php53-shmop-5.3.17-112.28.1 php53-snmp-5.3.17-112.28.1 php53-soap-5.3.17-112.28.1 php53-suhosin-5.3.17-112.28.1 php53-sysvmsg-5.3.17-112.28.1 php53-sysvsem-5.3.17-112.28.1 php53-sysvshm-5.3.17-112.28.1 php53-tokenizer-5.3.17-112.28.1 php53-wddx-5.3.17-112.28.1 php53-xmlreader-5.3.17-112.28.1 php53-xmlrpc-5.3.17-112.28.1 php53-xmlwriter-5.3.17-112.28.1 php53-xsl-5.3.17-112.28.1 php53-zip-5.3.17-112.28.1 php53-zlib-5.3.17-112.28.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-debuginfo-5.3.17-112.28.1 php53-debugsource-5.3.17-112.28.1 References: https://www.suse.com/security/cve/CVE-2018-10360.html https://www.suse.com/security/cve/CVE-2018-12882.html https://bugzilla.suse.com/1096984 https://bugzilla.suse.com/1099098 . SUSEPatch Notification: Resolutions for php53 vulnerabilities addressing denial of service and use-after-free with moderate risk.. SUSE Linux Patch, PHP53 Security Fixes, Linux Software Update. . LinuxSecurity.com Team
An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available.. SUSE Security Update: Security update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:0568-1 Rating: important References: #1019550 #1022219 #1022255 #1022257 #1022260 #1022263 #1022264 #1022265 Cross-References: CVE-2016-10158 CVE-2016-10159 CVE-2016-10160 CVE-2016-10161 CVE-2016-10166 CVE-2016-10167 CVE-2016-10168 CVE-2016-7478 Affected Products: SUSE OpenStack Cloud 5 SUSE Manager Proxy 2.1 SUSE Manager 2.1 SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes 8 vulnerabilities is now available. Description: This update for php53 fixes the following security issues: - CVE-2016-7478: When unserializing untrusted input data, PHP could end up in an infinite loop, causing denial of service (bsc#1019550) - CVE-2016-10158: The exif_convert_any_to_int function in ext/exif/exif.c in PHP allowed remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divide the minimum representable negative integer by -1. (bsc#1022219) - CVE-2016-10159: Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP allowed remote attackers to cause a denial of service (memory consumption or application crash)via a truncated manifest entry in a PHAR archive. (bsc#1022255) - CVE-2016-10160: Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP allowed remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch. (bsc#1022257) - CVE-2016-10161: The object_common1 function in ext/standard/var_unserializer.c in PHP allowed remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data that is mishandled in a finish_nested_data call. (bsc#1022260) - CVE-2016-10166: A potential unsigned underflow in gd interpolation functions could lead to memory corruption in the PHP gd module (bsc#1022263) - CVE-2016-10167: A denial of service problem in gdImageCreateFromGd2Ctx() could lead to php out of memory even on small files. (bsc#1022264) - CVE-2016-10168: A signed integer overflow in the gd module could lead to memory corruption (bsc#1022265) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 5: zypper in -t patch sleclo50sp3-php53-12997=1 - SUSE Manager Proxy 2.1: zypper in -t patch slemap21-php53-12997=1 - SUSE Manager 2.1: zypper in -t patch sleman21-php53-12997=1 - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-php53-12997=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-php53-12997=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-php53-12997=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-php53-12997=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-12997=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patchdbgsp3-php53-12997=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 5 (x86_64): apache2-mod_php53-5.3.17-101.1 php53-5.3.17-101.1 php53-bcmath-5.3.17-101.1 php53-bz2-5.3.17-101.1 php53-calendar-5.3.17-101.1 php53-ctype-5.3.17-101.1 php53-curl-5.3.17-101.1 php53-dba-5.3.17-101.1 php53-dom-5.3.17-101.1 php53-exif-5.3.17-101.1 php53-fastcgi-5.3.17-101.1 php53-fileinfo-5.3.17-101.1 php53-ftp-5.3.17-101.1 php53-gd-5.3.17-101.1 php53-gettext-5.3.17-101.1 php53-gmp-5.3.17-101.1 php53-iconv-5.3.17-101.1 php53-intl-5.3.17-101.1 php53-json-5.3.17-101.1 php53-ldap-5.3.17-101.1 php53-mbstring-5.3.17-101.1 php53-mcrypt-5.3.17-101.1 php53-mysql-5.3.17-101.1 php53-odbc-5.3.17-101.1 php53-openssl-5.3.17-101.1 php53-pcntl-5.3.17-101.1 php53-pdo-5.3.17-101.1 php53-pear-5.3.17-101.1 php53-pgsql-5.3.17-101.1 php53-pspell-5.3.17-101.1 php53-shmop-5.3.17-101.1 php53-snmp-5.3.17-101.1 php53-soap-5.3.17-101.1 php53-suhosin-5.3.17-101.1 php53-sysvmsg-5.3.17-101.1 php53-sysvsem-5.3.17-101.1 php53-sysvshm-5.3.17-101.1 php53-tokenizer-5.3.17-101.1 php53-wddx-5.3.17-101.1 php53-xmlreader-5.3.17-101.1 php53-xmlrpc-5.3.17-101.1 php53-xmlwriter-5.3.17-101.1 php53-xsl-5.3.17-101.1 php53-zip-5.3.17-101.1 php53-zlib-5.3.17-101.1 - SUSE Manager Proxy 2.1 (x86_64): apache2-mod_php53-5.3.17-101.1 php53-5.3.17-101.1 php53-bcmath-5.3.17-101.1 php53-bz2-5.3.17-101.1 php53-calendar-5.3.17-101.1 php53-ctype-5.3.17-101.1 php53-curl-5.3.17-101.1 php53-dba-5.3.17-101.1 php53-dom-5.3.17-101.1 php53-exif-5.3.17-101.1 php53-fastcgi-5.3.17-101.1 php53-fileinfo-5.3.17-101.1 php53-ftp-5.3.17-101.1 php53-gd-5.3.17-101.1 php53-gettext-5.3.17-101.1 php53-gmp-5.3.17-101.1 php53-iconv-5.3.17-101.1 php53-intl-5.3.17-101.1 php53-json-5.3.17-101.1 php53-ldap-5.3.17-101.1 php53-mbstring-5.3.17-101.1 php53-mcrypt-5.3.17-101.1 php53-mysql-5.3.17-101.1 php53-odbc-5.3.17-101.1 php53-openssl-5.3.17-101.1 php53-pcntl-5.3.17-101.1 php53-pdo-5.3.17-101.1 php53-pear-5.3.17-101.1 php53-pgsql-5.3.17-101.1 php53-pspell-5.3.17-101.1 php53-shmop-5.3.17-101.1 php53-snmp-5.3.17-101.1 php53-soap-5.3.17-101.1 php53-suhosin-5.3.17-101.1 php53-sysvmsg-5.3.17-101.1 php53-sysvsem-5.3.17-101.1 php53-sysvshm-5.3.17-101.1 php53-tokenizer-5.3.17-101.1 php53-wddx-5.3.17-101.1 php53-xmlreader-5.3.17-101.1 php53-xmlrpc-5.3.17-101.1 php53-xmlwriter-5.3.17-101.1 php53-xsl-5.3.17-101.1 php53-zip-5.3.17-101.1 php53-zlib-5.3.17-101.1 - SUSE Manager 2.1 (s390x x86_64): apache2-mod_php53-5.3.17-101.1 php53-5.3.17-101.1 php53-bcmath-5.3.17-101.1 php53-bz2-5.3.17-101.1 php53-calendar-5.3.17-101.1 php53-ctype-5.3.17-101.1 php53-curl-5.3.17-101.1 php53-dba-5.3.17-101.1 php53-dom-5.3.17-101.1 php53-exif-5.3.17-101.1 php53-fastcgi-5.3.17-101.1 php53-fileinfo-5.3.17-101.1 php53-ftp-5.3.17-101.1 php53-gd-5.3.17-101.1 php53-gettext-5.3.17-101.1 php53-gmp-5.3.17-101.1 php53-iconv-5.3.17-101.1 php53-intl-5.3.17-101.1 php53-json-5.3.17-101.1 php53-ldap-5.3.17-101.1 php53-mbstring-5.3.17-101.1 php53-mcrypt-5.3.17-101.1 php53-mysql-5.3.17-101.1 php53-odbc-5.3.17-101.1 php53-openssl-5.3.17-101.1 php53-pcntl-5.3.17-101.1 php53-pdo-5.3.17-101.1 php53-pear-5.3.17-101.1 php53-pgsql-5.3.17-101.1 php53-pspell-5.3.17-101.1 php53-shmop-5.3.17-101.1 php53-snmp-5.3.17-101.1 php53-soap-5.3.17-101.1 php53-suhosin-5.3.17-101.1 php53-sysvmsg-5.3.17-101.1 php53-sysvsem-5.3.17-101.1 php53-sysvshm-5.3.17-101.1 php53-tokenizer-5.3.17-101.1 php53-wddx-5.3.17-101.1 php53-xmlreader-5.3.17-101.1 php53-xmlrpc-5.3.17-101.1 php53-xmlwriter-5.3.17-101.1 php53-xsl-5.3.17-101.1 php53-zip-5.3.17-101.1 php53-zlib-5.3.17-101.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-devel-5.3.17-101.1 php53-imap-5.3.17-101.1 php53-posix-5.3.17-101.1 php53-readline-5.3.17-101.1 php53-sockets-5.3.17-101.1 php53-sqlite-5.3.17-101.1 php53-tidy-5.3.17-101.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-101.1 php53-5.3.17-101.1 php53-bcmath-5.3.17-101.1 php53-bz2-5.3.17-101.1 php53-calendar-5.3.17-101.1 php53-ctype-5.3.17-101.1 php53-curl-5.3.17-101.1 php53-dba-5.3.17-101.1 php53-dom-5.3.17-101.1 php53-exif-5.3.17-101.1 php53-fastcgi-5.3.17-101.1 php53-fileinfo-5.3.17-101.1 php53-ftp-5.3.17-101.1 php53-gd-5.3.17-101.1 php53-gettext-5.3.17-101.1 php53-gmp-5.3.17-101.1 php53-iconv-5.3.17-101.1 php53-intl-5.3.17-101.1 php53-json-5.3.17-101.1 php53-ldap-5.3.17-101.1 php53-mbstring-5.3.17-101.1 php53-mcrypt-5.3.17-101.1 php53-mysql-5.3.17-101.1 php53-odbc-5.3.17-101.1 php53-openssl-5.3.17-101.1 php53-pcntl-5.3.17-101.1 php53-pdo-5.3.17-101.1 php53-pear-5.3.17-101.1 php53-pgsql-5.3.17-101.1 php53-pspell-5.3.17-101.1 php53-shmop-5.3.17-101.1 php53-snmp-5.3.17-101.1 php53-soap-5.3.17-101.1 php53-suhosin-5.3.17-101.1 php53-sysvmsg-5.3.17-101.1 php53-sysvsem-5.3.17-101.1 php53-sysvshm-5.3.17-101.1 php53-tokenizer-5.3.17-101.1 php53-wddx-5.3.17-101.1 php53-xmlreader-5.3.17-101.1 php53-xmlrpc-5.3.17-101.1 php53-xmlwriter-5.3.17-101.1 php53-xsl-5.3.17-101.1 php53-zip-5.3.17-101.1 php53-zlib-5.3.17-101.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): apache2-mod_php53-5.3.17-101.1 php53-5.3.17-101.1 php53-bcmath-5.3.17-101.1 php53-bz2-5.3.17-101.1 php53-calendar-5.3.17-101.1 php53-ctype-5.3.17-101.1 php53-curl-5.3.17-101.1 php53-dba-5.3.17-101.1 php53-dom-5.3.17-101.1 php53-exif-5.3.17-101.1 php53-fastcgi-5.3.17-101.1 php53-fileinfo-5.3.17-101.1 php53-ftp-5.3.17-101.1 php53-gd-5.3.17-101.1 php53-gettext-5.3.17-101.1 php53-gmp-5.3.17-101.1 php53-iconv-5.3.17-101.1 php53-intl-5.3.17-101.1 php53-json-5.3.17-101.1 php53-ldap-5.3.17-101.1 php53-mbstring-5.3.17-101.1 php53-mcrypt-5.3.17-101.1 php53-mysql-5.3.17-101.1 php53-odbc-5.3.17-101.1 php53-openssl-5.3.17-101.1 php53-pcntl-5.3.17-101.1 php53-pdo-5.3.17-101.1 php53-pear-5.3.17-101.1 php53-pgsql-5.3.17-101.1 php53-pspell-5.3.17-101.1 php53-shmop-5.3.17-101.1 php53-snmp-5.3.17-101.1 php53-soap-5.3.17-101.1 php53-suhosin-5.3.17-101.1 php53-sysvmsg-5.3.17-101.1 php53-sysvsem-5.3.17-101.1 php53-sysvshm-5.3.17-101.1 php53-tokenizer-5.3.17-101.1 php53-wddx-5.3.17-101.1 php53-xmlreader-5.3.17-101.1 php53-xmlrpc-5.3.17-101.1 php53-xmlwriter-5.3.17-101.1 php53-xsl-5.3.17-101.1 php53-zip-5.3.17-101.1 php53-zlib-5.3.17-101.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): apache2-mod_php53-5.3.17-101.1 php53-5.3.17-101.1 php53-bcmath-5.3.17-101.1 php53-bz2-5.3.17-101.1 php53-calendar-5.3.17-101.1 php53-ctype-5.3.17-101.1 php53-curl-5.3.17-101.1 php53-dba-5.3.17-101.1 php53-dom-5.3.17-101.1 php53-exif-5.3.17-101.1 php53-fastcgi-5.3.17-101.1 php53-fileinfo-5.3.17-101.1 php53-ftp-5.3.17-101.1 php53-gd-5.3.17-101.1 php53-gettext-5.3.17-101.1 php53-gmp-5.3.17-101.1 php53-iconv-5.3.17-101.1 php53-intl-5.3.17-101.1 php53-json-5.3.17-101.1 php53-ldap-5.3.17-101.1 php53-mbstring-5.3.17-101.1 php53-mcrypt-5.3.17-101.1 php53-mysql-5.3.17-101.1 php53-odbc-5.3.17-101.1 php53-openssl-5.3.17-101.1 php53-pcntl-5.3.17-101.1 php53-pdo-5.3.17-101.1 php53-pear-5.3.17-101.1 php53-pgsql-5.3.17-101.1 php53-pspell-5.3.17-101.1 php53-shmop-5.3.17-101.1 php53-snmp-5.3.17-101.1 php53-soap-5.3.17-101.1 php53-suhosin-5.3.17-101.1 php53-sysvmsg-5.3.17-101.1 php53-sysvsem-5.3.17-101.1 php53-sysvshm-5.3.17-101.1 php53-tokenizer-5.3.17-101.1 php53-wddx-5.3.17-101.1 php53-xmlreader-5.3.17-101.1 php53-xmlrpc-5.3.17-101.1 php53-xmlwriter-5.3.17-101.1 php53-xsl-5.3.17-101.1 php53-zip-5.3.17-101.1 php53-zlib-5.3.17-101.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-debuginfo-5.3.17-101.1 php53-debugsource-5.3.17-101.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): php53-debuginfo-5.3.17-101.1 php53-debugsource-5.3.17-101.1 References: https://www.suse.com/security/cve/CVE-2016-10158.html https://www.suse.com/security/cve/CVE-2016-10159.html https://www.suse.com/security/cve/CVE-2016-10160.html https://www.suse.com/security/cve/CVE-2016-10161.html https://www.suse.com/security/cve/CVE-2016-10166.html https://www.suse.com/security/cve/CVE-2016-10167.html https://www.suse.com/security/cve/CVE-2016-10168.html https://www.suse.com/security/cve/CVE-2016-7478.html https://bugzilla.suse.com/1019550 https://bugzilla.suse.com/1022219 https://bugzilla.suse.com/1022255 https://bugzilla.suse.com/1022257 https://bugzilla.suse.com/1022260 https://bugzilla.suse.com/1022263 https://bugzilla.suse.com/1022264 https://bugzilla.suse.com/1022265 . SUSE enhances php53 to address 8 severe security flaws. Maintain safety by checking the updated patch guidelines and procedures.. SUSE PHP Update, Security Patch, Denial of Service, Software Vulnerability, Memory Corruption. . Severity: Important. LinuxSecurity.com Team
An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.. SUSE Security Update: Security update for php53 ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:2459-1 Rating: important References: #997206 #997207 #997208 #997210 #997211 #997220 #997225 #997230 #997257 #999679 #999680 #999682 #999684 #999685 #999819 #999820 Cross-References: CVE-2016-7124 CVE-2016-7125 CVE-2016-7126 CVE-2016-7127 CVE-2016-7128 CVE-2016-7129 CVE-2016-7130 CVE-2016-7131 CVE-2016-7132 CVE-2016-7411 CVE-2016-7412 CVE-2016-7413 CVE-2016-7414 CVE-2016-7416 CVE-2016-7417 CVE-2016-7418 Affected Products: SUSE OpenStack Cloud 5 SUSE Manager Proxy 2.1 SUSE Manager 2.1 SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes 16 vulnerabilities is now available. Description: This update for php53 fixes the following security issues: * CVE-2016-7124: Create an Unexpected Object and Don't Invoke __wakeup() in Deserialization * CVE-2016-7125: PHP Session Data Injection Vulnerability * CVE-2016-7126: select_colors write out-of-bounds * CVE-2016-7127: imagegammacorrect allowed arbitrary write access * CVE-2016-7128: Memory Leakage In exif_process_IFD_in_TIFF * CVE-2016-7129: wddx_deserialize allows illegalmemory access * CVE-2016-7130: wddx_deserialize null dereference * CVE-2016-7131: wddx_deserialize null dereference with invalid xml * CVE-2016-7132: wddx_deserialize null dereference in php_wddx_pop_element * CVE-2016-7411: php5: Memory corruption when destructing deserialized object * CVE-2016-7412: Heap overflow in mysqlnd when not receiving UNSIGNED_FLAG in BIT field * CVE-2016-7413: Use after free in wddx_deserialize * CVE-2016-7414: Out of bounds heap read when verifying signature of zip phar in phar_parse_zipfile * CVE-2016-7416: Stack based buffer overflow in msgfmt_format_message * CVE-2016-7417: Missing type check when unserializing SplArray * CVE-2016-7418: Null pointer dereference in php_wddx_push_element Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 5: zypper in -t patch sleclo50sp3-php53-12775=1 - SUSE Manager Proxy 2.1: zypper in -t patch slemap21-php53-12775=1 - SUSE Manager 2.1: zypper in -t patch sleman21-php53-12775=1 - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-php53-12775=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-php53-12775=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-php53-12775=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-php53-12775=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-php53-12775=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-php53-12775=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 5 (x86_64): apache2-mod_php53-5.3.17-84.1 php53-5.3.17-84.1 php53-bcmath-5.3.17-84.1 php53-bz2-5.3.17-84.1 php53-calendar-5.3.17-84.1 php53-ctype-5.3.17-84.1 php53-curl-5.3.17-84.1 php53-dba-5.3.17-84.1 php53-dom-5.3.17-84.1 php53-exif-5.3.17-84.1 php53-fastcgi-5.3.17-84.1 php53-fileinfo-5.3.17-84.1 php53-ftp-5.3.17-84.1 php53-gd-5.3.17-84.1 php53-gettext-5.3.17-84.1 php53-gmp-5.3.17-84.1 php53-iconv-5.3.17-84.1 php53-intl-5.3.17-84.1 php53-json-5.3.17-84.1 php53-ldap-5.3.17-84.1 php53-mbstring-5.3.17-84.1 php53-mcrypt-5.3.17-84.1 php53-mysql-5.3.17-84.1 php53-odbc-5.3.17-84.1 php53-openssl-5.3.17-84.1 php53-pcntl-5.3.17-84.1 php53-pdo-5.3.17-84.1 php53-pear-5.3.17-84.1 php53-pgsql-5.3.17-84.1 php53-pspell-5.3.17-84.1 php53-shmop-5.3.17-84.1 php53-snmp-5.3.17-84.1 php53-soap-5.3.17-84.1 php53-suhosin-5.3.17-84.1 php53-sysvmsg-5.3.17-84.1 php53-sysvsem-5.3.17-84.1 php53-sysvshm-5.3.17-84.1 php53-tokenizer-5.3.17-84.1 php53-wddx-5.3.17-84.1 php53-xmlreader-5.3.17-84.1 php53-xmlrpc-5.3.17-84.1 php53-xmlwriter-5.3.17-84.1 php53-xsl-5.3.17-84.1 php53-zip-5.3.17-84.1 php53-zlib-5.3.17-84.1 - SUSE Manager Proxy 2.1 (x86_64): apache2-mod_php53-5.3.17-84.1 php53-5.3.17-84.1 php53-bcmath-5.3.17-84.1 php53-bz2-5.3.17-84.1 php53-calendar-5.3.17-84.1 php53-ctype-5.3.17-84.1 php53-curl-5.3.17-84.1 php53-dba-5.3.17-84.1 php53-dom-5.3.17-84.1 php53-exif-5.3.17-84.1 php53-fastcgi-5.3.17-84.1 php53-fileinfo-5.3.17-84.1 php53-ftp-5.3.17-84.1 php53-gd-5.3.17-84.1 php53-gettext-5.3.17-84.1 php53-gmp-5.3.17-84.1 php53-iconv-5.3.17-84.1 php53-intl-5.3.17-84.1 php53-json-5.3.17-84.1 php53-ldap-5.3.17-84.1 php53-mbstring-5.3.17-84.1 php53-mcrypt-5.3.17-84.1 php53-mysql-5.3.17-84.1 php53-odbc-5.3.17-84.1 php53-openssl-5.3.17-84.1 php53-pcntl-5.3.17-84.1 php53-pdo-5.3.17-84.1 php53-pear-5.3.17-84.1 php53-pgsql-5.3.17-84.1 php53-pspell-5.3.17-84.1 php53-shmop-5.3.17-84.1 php53-snmp-5.3.17-84.1 php53-soap-5.3.17-84.1 php53-suhosin-5.3.17-84.1 php53-sysvmsg-5.3.17-84.1 php53-sysvsem-5.3.17-84.1 php53-sysvshm-5.3.17-84.1 php53-tokenizer-5.3.17-84.1 php53-wddx-5.3.17-84.1 php53-xmlreader-5.3.17-84.1 php53-xmlrpc-5.3.17-84.1 php53-xmlwriter-5.3.17-84.1 php53-xsl-5.3.17-84.1 php53-zip-5.3.17-84.1 php53-zlib-5.3.17-84.1 - SUSE Manager 2.1 (s390x x86_64): apache2-mod_php53-5.3.17-84.1 php53-5.3.17-84.1 php53-bcmath-5.3.17-84.1 php53-bz2-5.3.17-84.1 php53-calendar-5.3.17-84.1 php53-ctype-5.3.17-84.1 php53-curl-5.3.17-84.1 php53-dba-5.3.17-84.1 php53-dom-5.3.17-84.1 php53-exif-5.3.17-84.1 php53-fastcgi-5.3.17-84.1 php53-fileinfo-5.3.17-84.1 php53-ftp-5.3.17-84.1 php53-gd-5.3.17-84.1 php53-gettext-5.3.17-84.1 php53-gmp-5.3.17-84.1 php53-iconv-5.3.17-84.1 php53-intl-5.3.17-84.1 php53-json-5.3.17-84.1 php53-ldap-5.3.17-84.1 php53-mbstring-5.3.17-84.1 php53-mcrypt-5.3.17-84.1 php53-mysql-5.3.17-84.1 php53-odbc-5.3.17-84.1 php53-openssl-5.3.17-84.1 php53-pcntl-5.3.17-84.1 php53-pdo-5.3.17-84.1 php53-pear-5.3.17-84.1 php53-pgsql-5.3.17-84.1 php53-pspell-5.3.17-84.1 php53-shmop-5.3.17-84.1 php53-snmp-5.3.17-84.1 php53-soap-5.3.17-84.1 php53-suhosin-5.3.17-84.1 php53-sysvmsg-5.3.17-84.1 php53-sysvsem-5.3.17-84.1 php53-sysvshm-5.3.17-84.1 php53-tokenizer-5.3.17-84.1 php53-wddx-5.3.17-84.1 php53-xmlreader-5.3.17-84.1 php53-xmlrpc-5.3.17-84.1 php53-xmlwriter-5.3.17-84.1 php53-xsl-5.3.17-84.1 php53-zip-5.3.17-84.1 php53-zlib-5.3.17-84.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-devel-5.3.17-84.1 php53-imap-5.3.17-84.1 php53-posix-5.3.17-84.1 php53-readline-5.3.17-84.1 php53-sockets-5.3.17-84.1 php53-sqlite-5.3.17-84.1 php53-tidy-5.3.17-84.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-84.1 php53-5.3.17-84.1 php53-bcmath-5.3.17-84.1 php53-bz2-5.3.17-84.1 php53-calendar-5.3.17-84.1 php53-ctype-5.3.17-84.1 php53-curl-5.3.17-84.1 php53-dba-5.3.17-84.1 php53-dom-5.3.17-84.1 php53-exif-5.3.17-84.1 php53-fastcgi-5.3.17-84.1 php53-fileinfo-5.3.17-84.1 php53-ftp-5.3.17-84.1 php53-gd-5.3.17-84.1 php53-gettext-5.3.17-84.1 php53-gmp-5.3.17-84.1 php53-iconv-5.3.17-84.1 php53-intl-5.3.17-84.1 php53-json-5.3.17-84.1 php53-ldap-5.3.17-84.1 php53-mbstring-5.3.17-84.1 php53-mcrypt-5.3.17-84.1 php53-mysql-5.3.17-84.1 php53-odbc-5.3.17-84.1 php53-openssl-5.3.17-84.1 php53-pcntl-5.3.17-84.1 php53-pdo-5.3.17-84.1 php53-pear-5.3.17-84.1 php53-pgsql-5.3.17-84.1 php53-pspell-5.3.17-84.1 php53-shmop-5.3.17-84.1 php53-snmp-5.3.17-84.1 php53-soap-5.3.17-84.1 php53-suhosin-5.3.17-84.1 php53-sysvmsg-5.3.17-84.1 php53-sysvsem-5.3.17-84.1 php53-sysvshm-5.3.17-84.1 php53-tokenizer-5.3.17-84.1 php53-wddx-5.3.17-84.1 php53-xmlreader-5.3.17-84.1 php53-xmlrpc-5.3.17-84.1 php53-xmlwriter-5.3.17-84.1 php53-xsl-5.3.17-84.1 php53-zip-5.3.17-84.1 php53-zlib-5.3.17-84.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): apache2-mod_php53-5.3.17-84.1 php53-5.3.17-84.1 php53-bcmath-5.3.17-84.1 php53-bz2-5.3.17-84.1 php53-calendar-5.3.17-84.1 php53-ctype-5.3.17-84.1 php53-curl-5.3.17-84.1 php53-dba-5.3.17-84.1 php53-dom-5.3.17-84.1 php53-exif-5.3.17-84.1 php53-fastcgi-5.3.17-84.1 php53-fileinfo-5.3.17-84.1 php53-ftp-5.3.17-84.1 php53-gd-5.3.17-84.1 php53-gettext-5.3.17-84.1 php53-gmp-5.3.17-84.1 php53-iconv-5.3.17-84.1 php53-intl-5.3.17-84.1 php53-json-5.3.17-84.1 php53-ldap-5.3.17-84.1 php53-mbstring-5.3.17-84.1 php53-mcrypt-5.3.17-84.1 php53-mysql-5.3.17-84.1 php53-odbc-5.3.17-84.1 php53-openssl-5.3.17-84.1 php53-pcntl-5.3.17-84.1 php53-pdo-5.3.17-84.1 php53-pear-5.3.17-84.1 php53-pgsql-5.3.17-84.1 php53-pspell-5.3.17-84.1 php53-shmop-5.3.17-84.1 php53-snmp-5.3.17-84.1 php53-soap-5.3.17-84.1 php53-suhosin-5.3.17-84.1 php53-sysvmsg-5.3.17-84.1 php53-sysvsem-5.3.17-84.1 php53-sysvshm-5.3.17-84.1 php53-tokenizer-5.3.17-84.1 php53-wddx-5.3.17-84.1 php53-xmlreader-5.3.17-84.1 php53-xmlrpc-5.3.17-84.1 php53-xmlwriter-5.3.17-84.1 php53-xsl-5.3.17-84.1 php53-zip-5.3.17-84.1 php53-zlib-5.3.17-84.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): apache2-mod_php53-5.3.17-84.1 php53-5.3.17-84.1 php53-bcmath-5.3.17-84.1 php53-bz2-5.3.17-84.1 php53-calendar-5.3.17-84.1 php53-ctype-5.3.17-84.1 php53-curl-5.3.17-84.1 php53-dba-5.3.17-84.1 php53-dom-5.3.17-84.1 php53-exif-5.3.17-84.1 php53-fastcgi-5.3.17-84.1 php53-fileinfo-5.3.17-84.1 php53-ftp-5.3.17-84.1 php53-gd-5.3.17-84.1 php53-gettext-5.3.17-84.1 php53-gmp-5.3.17-84.1 php53-iconv-5.3.17-84.1 php53-intl-5.3.17-84.1 php53-json-5.3.17-84.1 php53-ldap-5.3.17-84.1 php53-mbstring-5.3.17-84.1 php53-mcrypt-5.3.17-84.1 php53-mysql-5.3.17-84.1 php53-odbc-5.3.17-84.1 php53-openssl-5.3.17-84.1 php53-pcntl-5.3.17-84.1 php53-pdo-5.3.17-84.1 php53-pear-5.3.17-84.1 php53-pgsql-5.3.17-84.1 php53-pspell-5.3.17-84.1 php53-shmop-5.3.17-84.1 php53-snmp-5.3.17-84.1 php53-soap-5.3.17-84.1 php53-suhosin-5.3.17-84.1 php53-sysvmsg-5.3.17-84.1 php53-sysvsem-5.3.17-84.1 php53-sysvshm-5.3.17-84.1 php53-tokenizer-5.3.17-84.1 php53-wddx-5.3.17-84.1 php53-xmlreader-5.3.17-84.1 php53-xmlrpc-5.3.17-84.1 php53-xmlwriter-5.3.17-84.1 php53-xsl-5.3.17-84.1 php53-zip-5.3.17-84.1 php53-zlib-5.3.17-84.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): php53-debuginfo-5.3.17-84.1 php53-debugsource-5.3.17-84.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): php53-debuginfo-5.3.17-84.1 php53-debugsource-5.3.17-84.1 References: https://www.suse.com/security/cve/CVE-2016-7124.html https://www.suse.com/security/cve/CVE-2016-7125.html https://www.suse.com/security/cve/CVE-2016-7126.html https://www.suse.com/security/cve/CVE-2016-7127.html https://www.suse.com/security/cve/CVE-2016-7128.html https://www.suse.com/security/cve/CVE-2016-7129.html https://www.suse.com/security/cve/CVE-2016-7130.html https://www.suse.com/security/cve/CVE-2016-7131.html https://www.suse.com/security/cve/CVE-2016-7132.html https://www.suse.com/security/cve/CVE-2016-7411.html https://www.suse.com/security/cve/CVE-2016-7412.html https://www.suse.com/security/cve/CVE-2016-7413.html https://www.suse.com/security/cve/CVE-2016-7414.html https://www.suse.com/security/cve/CVE-2016-7416.html https://www.suse.com/security/cve/CVE-2016-7417.html https://www.suse.com/security/cve/CVE-2016-7418.html https://bugzilla.suse.com/997206 https://bugzilla.suse.com/997207 https://bugzilla.suse.com/997208 https://bugzilla.suse.com/997210 https://bugzilla.suse.com/997211 https://bugzilla.suse.com/997220 https://bugzilla.suse.com/997225 https://bugzilla.suse.com/997230 https://bugzilla.suse.com/997257 https://bugzilla.suse.com/999679 https://bugzilla.suse.com/999680 https://bugzilla.suse.com/999682 https://bugzilla.suse.com/999684 https://bugzilla.suse.com/999685 https://bugzilla.suse.com/999819 https://bugzilla.suse.com/999820 . Important notice for SUSE Linux users regarding an update that resolves 16 critical vulnerabilities in php53, some of which are highly severe. Immediate action required!. SUSE Linux Security, PHP Security Issues, php53 Update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.