MGASA-2019-0412 - Updated php packages fix security vulnerabilities

Publication date: 25 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0412.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-11045,
     CVE-2019-11046,
     CVE-2019-11047,
     CVE-2019-11049,
     CVE-2019-11050

Updated php packages fix security vulnerabilities:

DirectoryIterator class silently truncates after a null byte
(CVE-2019-11045).

Buffer underflow in bc_shift_addsub). (CVE-2019-11046)

Heap-buffer-overflow READ in exif. (CVE-2019-11047)

mail() may release string with refcount==1 twice. (CVE-2019-11049)

Use-after-free in exif parsing under memory sanitizer). (CVE-2019-11050)

For other fixes, see the referenced changelog.

References:
- https://bugs.mageia.org/show_bug.cgi?id=25894
- https://www.php.net/ChangeLog-7.php#7.3.13
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11045
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11046
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11047
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11049
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11050

SRPMS:
- 7/core/php-7.3.13-1.mga7

Mageia 2019-0412: php security update

Updated php packages fix security vulnerabilities: DirectoryIterator class silently truncates after a null byte (CVE-2019-11045)

Summary

Updated php packages fix security vulnerabilities:
DirectoryIterator class silently truncates after a null byte (CVE-2019-11045).
Buffer underflow in bc_shift_addsub). (CVE-2019-11046)
Heap-buffer-overflow READ in exif. (CVE-2019-11047)
mail() may release string with refcount==1 twice. (CVE-2019-11049)
Use-after-free in exif parsing under memory sanitizer). (CVE-2019-11050)
For other fixes, see the referenced changelog.

References

- https://bugs.mageia.org/show_bug.cgi?id=25894

- https://www.php.net/ChangeLog-7.php#7.3.13

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11045

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11046

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11047

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11049

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11050

Resolution

MGASA-2019-0412 - Updated php packages fix security vulnerabilities

SRPMS

- 7/core/php-7.3.13-1.mga7

Severity
Publication date: 25 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0412.html
Type: security
CVE: CVE-2019-11045, CVE-2019-11046, CVE-2019-11047, CVE-2019-11049, CVE-2019-11050

Related News