shield
Security update for php7
SUSE-SLE-SDK-12-SP3-2017-1532
This update for php7 fixes several issues. These security issues were fixed: - CVE-2017-12932: Prevent heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array size. Exploitation of this issue could have had an unspecified impact on the integrity of PHP (bsc#1054432). - CVE-2017-12934: Prevent heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue could have had an unspecified impact on the integrity of PHP (bsc#1054408). - CVE-2017-12933: The finish_nested_data function in ext/standard/var_unserializer.re was prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue could have had an unspecified impact on the integrity of PHP (bsc#1054430) These non-security issues were fixed: - bsc#1057104: php7-devel now requires php7-pear - bsc#1057845: Fixed namespace encapsulation of imported classes/functions/constants
-
Release DateSep 14 2017
-
ReferencesBugzilla: 1057845, 1057104, 1054432, 1054408, 1054430
CVEs: CVE-2017-12933, CVE-2017-12934, CVE-2017-12932 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Software Development Kit 12.3 s390x
-
Packages
SUSE Linux Enterprise Software Development Kit 12.3 aarch64
-
Packages
SUSE Linux Enterprise Software Development Kit 12.3 ppc64le
-
Packages
SUSE Linux Enterprise Software Development Kit 12.3 x86_64
-
Packages