ELSA-2020-1112

ELSA-2020-1112 - php security update

Type:SECURITY
Severity:MODERATE
Release Date:2020-04-06

Description


[5.4.16-48]
- fix underflow in env_path_info in fpm_main.c CVE-2019-11043

[5.4.16-47]
- fix stack-buffer-overflow while parsing HTTP response CVE-2018-7584
- fix out-of-bounds read in base64_decode_xmlrpc CVE-2019-9024
- fix reflected XSS in phar 404 page CVE-2018-5712
- fix reflected XSS in phar 403 and 404 error pages CVE-2018-10547


Related CVEs


CVE-2018-5712
CVE-2019-9024
CVE-2018-7584
CVE-2018-10547

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) php-5.4.16-48.el7.src.rpm22816648733270847bf80a174cf4987b-
php-5.4.16-48.el7.aarch64.rpmd61b15966e2f3ee1a7e1a2338bf1b431-
php-bcmath-5.4.16-48.el7.aarch64.rpm659ce904a7471860ceed9a29cb48d118-
php-cli-5.4.16-48.el7.aarch64.rpm6e2bad4bd7359292dc73563c4b589741-
php-common-5.4.16-48.el7.aarch64.rpm42e14867df062500db102f7c20a675c5-
php-dba-5.4.16-48.el7.aarch64.rpmedb0b3b423dc4aa5dfc32356ad986924-
php-devel-5.4.16-48.el7.aarch64.rpmf430dcc5ca00eeac0397f52503a7036e-
php-embedded-5.4.16-48.el7.aarch64.rpma8b9bcc6ecc5b72800c0c025ee955f18-
php-enchant-5.4.16-48.el7.aarch64.rpmd484adb3dfb3a4a174b518c2562347ef-
php-fpm-5.4.16-48.el7.aarch64.rpm4c31eca60ebdaabc3b29080e05f3d453-
php-gd-5.4.16-48.el7.aarch64.rpmb0a9049f7031a0adfe88469ac15a04fc-
php-intl-5.4.16-48.el7.aarch64.rpm62f188c12ebf4c5faef1485fc0be9532-
php-ldap-5.4.16-48.el7.aarch64.rpma1c88c1e41da5b7caa3cf10be408711d-
php-mbstring-5.4.16-48.el7.aarch64.rpm7b8097b51b9e23478bca94d93770e6ee-
php-mysql-5.4.16-48.el7.aarch64.rpmfc812fa8e44519747ceb8e0f121b4d35-
php-mysqlnd-5.4.16-48.el7.aarch64.rpm30d8fd1efb0e1aca06be91cd88cf9629-
php-odbc-5.4.16-48.el7.aarch64.rpm11a29f7ad9f1410e862304565fc023bf-
php-pdo-5.4.16-48.el7.aarch64.rpmd149bfdbe338aa672fe6e2ab826ccc28-
php-pgsql-5.4.16-48.el7.aarch64.rpm478bf00169c1564283849ccff20a68e9-
php-process-5.4.16-48.el7.aarch64.rpmf1ea211e5fa4c0afc425daeb7c779b3c-
php-pspell-5.4.16-48.el7.aarch64.rpm9c8f1691f13faf738f3013c529f550d7-
php-recode-5.4.16-48.el7.aarch64.rpm07267b940c3b8f76973bc331aeba60bb-
php-snmp-5.4.16-48.el7.aarch64.rpm902491d00e1f079c4b93b546441e2ed0-
php-soap-5.4.16-48.el7.aarch64.rpm03b16d7d0eda8d3bf83d0631d33857bc-
php-xml-5.4.16-48.el7.aarch64.rpm427864baa7df15da5d6606d840196088-
php-xmlrpc-5.4.16-48.el7.aarch64.rpm674984c48a9681057c8799c666af65d1-
Oracle Linux 7 (x86_64) php-5.4.16-48.el7.src.rpm22816648733270847bf80a174cf4987b-
php-5.4.16-48.el7.x86_64.rpm8f169e66296062156da938864bc3cea7-
php-bcmath-5.4.16-48.el7.x86_64.rpm7582293bdf0ef6c9f43786a457d7298a-
php-cli-5.4.16-48.el7.x86_64.rpm9aa7f75d1fd8c669aa46768050e2fa7e-
php-common-5.4.16-48.el7.x86_64.rpmb399c4bb247ea55b27c9650e296fcd9c-
php-dba-5.4.16-48.el7.x86_64.rpme61500e41b4ffdbf8f44bf742b04c241-
php-devel-5.4.16-48.el7.x86_64.rpm47cf6e1b8d1d5befbf001111aadfb3b8-
php-embedded-5.4.16-48.el7.x86_64.rpmdba48d1229bf02552210288efb96b946-
php-enchant-5.4.16-48.el7.x86_64.rpm1cae58051558a460574a2c283cc525db-
php-fpm-5.4.16-48.el7.x86_64.rpm23f28b4470b8768c37bcad1731f465f8-
php-gd-5.4.16-48.el7.x86_64.rpmb76f3324e49bb1123ce545b16518e3f6-
php-intl-5.4.16-48.el7.x86_64.rpma88a30a763e77d66362976e0e83352fe-
php-ldap-5.4.16-48.el7.x86_64.rpm9f06305ef984b5c59ccdb96f03a88750-
php-mbstring-5.4.16-48.el7.x86_64.rpm70b46dea8c5d6f9cccdf152138bb0801-
php-mysql-5.4.16-48.el7.x86_64.rpm17b252c198d73167c5ecac20cccd15cc-
php-mysqlnd-5.4.16-48.el7.x86_64.rpm52f4a977f3c5e0182a589c11a58d3a0e-
php-odbc-5.4.16-48.el7.x86_64.rpmd1d9189fb943e84818fcc0bcaf472a73-
php-pdo-5.4.16-48.el7.x86_64.rpmebde4d68e2950e59802b94c9b9d688be-
php-pgsql-5.4.16-48.el7.x86_64.rpmca576e43ab2d849b8b2192bf079a5ec0-
php-process-5.4.16-48.el7.x86_64.rpm7f7d1a9afb2d0998a35f37fe71792091-
php-pspell-5.4.16-48.el7.x86_64.rpm4420909c1bb3d6b7745c25e730b737e9-
php-recode-5.4.16-48.el7.x86_64.rpm6ccc4ab2c0af91c965bf2209b38d4e5d-
php-snmp-5.4.16-48.el7.x86_64.rpmb0a883e9d41fa5decccbbd4eb7484cad-
php-soap-5.4.16-48.el7.x86_64.rpm643f337be83461d86475630b3a97fdc5-
php-xml-5.4.16-48.el7.x86_64.rpmffff085c205b631b1366b32f9ceb55b9-
php-xmlrpc-5.4.16-48.el7.x86_64.rpm74045e29ed3123197ae1bb5b3a5933ed-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete