ELSA-2014-1327

ELSA-2014-1327 - php security update

Type:SECURITY
Severity:MODERATE
Release Date:2014-09-30

Description


[5.4.16-23.1]
- gd: fix NULL pointer dereference in gdImageCreateFromXpm().
CVE-2014-2497
- gd: fix NUL byte injection in file names. CVE-2014-5120
- fileinfo: fix extensive backtracking in regular expression
(incomplete fix for CVE-2013-7345). CVE-2014-3538
- fileinfo: fix mconvert incorrect handling of truncated
pascal string size. CVE-2014-3478
- fileinfo: fix cdf_read_property_info
(incomplete fix for CVE-2012-1571). CVE-2014-3587
- spl: fix use-after-free in ArrayIterator due to object
change during sorting. CVE-2014-4698
- spl: fix use-after-free in SPL Iterators. CVE-2014-4670
- network: fix segfault in dns_get_record
(incomplete fix for CVE-2014-4049). CVE-2014-3597


Related CVEs


CVE-2014-2497
CVE-2014-3478
CVE-2014-3538
CVE-2014-3587
CVE-2014-3597
CVE-2014-4670
CVE-2014-4698
CVE-2014-5120

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) php-5.4.16-23.el7_0.1.src.rpm7e68f778840f607f46b067453484f834ELSA-2020-1112
php-5.4.16-23.el7_0.1.x86_64.rpm58c81605363dc3ab3557689b8ae8591cELSA-2020-1112
php-bcmath-5.4.16-23.el7_0.1.x86_64.rpm98fbde3068e5af8ea4f24e4b53d6eb36ELSA-2020-1112
php-cli-5.4.16-23.el7_0.1.x86_64.rpm827f3f2e410e6b334559efbf4754eb95ELSA-2020-1112
php-common-5.4.16-23.el7_0.1.x86_64.rpm6a1c540510d27bb652bb30a1d720a872ELSA-2020-1112
php-dba-5.4.16-23.el7_0.1.x86_64.rpm10b0c107bb5c2dd6d4ae164ff6245bb0ELSA-2020-1112
php-devel-5.4.16-23.el7_0.1.x86_64.rpme1f3e79ee591fed2243737ac3dd33597ELSA-2020-1112
php-embedded-5.4.16-23.el7_0.1.x86_64.rpma6e4093f59aa0aa0b1171d2eb0633882ELSA-2020-1112
php-enchant-5.4.16-23.el7_0.1.x86_64.rpm78426dce74325619a89885277f0d707bELSA-2020-1112
php-fpm-5.4.16-23.el7_0.1.x86_64.rpmc06ddfb042a1312cda9f6407f0088f97ELSA-2020-1112
php-gd-5.4.16-23.el7_0.1.x86_64.rpma8dc891a4e950b7cf75b82e7fd7a76d4ELSA-2020-1112
php-intl-5.4.16-23.el7_0.1.x86_64.rpm3c79eac28ae8c5b52ffd3cdaa24e3cedELSA-2020-1112
php-ldap-5.4.16-23.el7_0.1.x86_64.rpm779d6735879a5ca6960dde7ae9507262ELSA-2020-1112
php-mbstring-5.4.16-23.el7_0.1.x86_64.rpm75baf421083a8d1e4117b46cffc39709ELSA-2020-1112
php-mysql-5.4.16-23.el7_0.1.x86_64.rpmba875bb4343250f2866b4cd96111f6feELSA-2020-1112
php-mysqlnd-5.4.16-23.el7_0.1.x86_64.rpm6be03c05b06d6f8577396e2ae2a4560aELSA-2020-1112
php-odbc-5.4.16-23.el7_0.1.x86_64.rpm2bef4a9a044fdecdc7d5b2f3ce3d57ceELSA-2020-1112
php-pdo-5.4.16-23.el7_0.1.x86_64.rpma5036a776d2e67afb597e7c4edf6509bELSA-2020-1112
php-pgsql-5.4.16-23.el7_0.1.x86_64.rpm3b44f461fbdc97d2ac73c8c96a97121eELSA-2020-1112
php-process-5.4.16-23.el7_0.1.x86_64.rpmba1ab9c8c92db953d1bda1b62b73d784ELSA-2020-1112
php-pspell-5.4.16-23.el7_0.1.x86_64.rpmcfdff28669b9310e44181c48aae6623dELSA-2020-1112
php-recode-5.4.16-23.el7_0.1.x86_64.rpm7dfa78d1746902146f2ce24bbb5b18a9ELSA-2020-1112
php-snmp-5.4.16-23.el7_0.1.x86_64.rpm95bb747a1da81d5b383e6c6a0305fe8cELSA-2020-1112
php-soap-5.4.16-23.el7_0.1.x86_64.rpm93b17a86e312f78f746d4f8a02f5cfa5ELSA-2020-1112
php-xml-5.4.16-23.el7_0.1.x86_64.rpma0ebedb06e1ab7089d2729c7a5c5271dELSA-2020-1112
php-xmlrpc-5.4.16-23.el7_0.1.x86_64.rpm25e55f428b473d212b2817b37a099989ELSA-2020-1112



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete