Security update for php5
This update for php5 fixes the following security issues: * CVE-2016-7411: php5: Memory corruption when destructing deserialized object * CVE-2016-7412: Heap overflow in mysqlnd when not receiving UNSIGNED_FLAG in BIT field * CVE-2016-7413: Use after free in wddx_deserialize * CVE-2016-7414: Out of bounds heap read when verifying signature of zip phar in phar_parse_zipfile * CVE-2016-7416: Stack based buffer overflow in msgfmt_format_message * CVE-2016-7417: Missing type check when unserializing SplArray * CVE-2016-7418: Null pointer dereference in php_wddx_push_element
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for php5 fixes the following security issues: * CVE-2016-7411: php5: Memory corruption when destructing deserialized object * CVE-2016-7412: Heap overflow in mysqlnd when not receiving UNSIGNED_FLAG in BIT field * CVE-2016-7413: Use after free in wddx_deserialize * CVE-2016-7414: Out of bounds heap read when verifying signature of zip phar in phar_parse_zipfile * CVE-2016-7416: Stack based buffer overflow in msgfmt_format_message * CVE-2016-7417: Missing type check when unserializing SplArray * CVE-2016-7418: Null pointer dereference in php_wddx_push_element
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/999679
- https://bugzilla.suse.com/999680
- https://bugzilla.suse.com/999682
- https://bugzilla.suse.com/999684
- https://bugzilla.suse.com/999685
- https://bugzilla.suse.com/999819
- https://bugzilla.suse.com/999820
- https://www.suse.com/security/cve/CVE-2016-7411
- https://www.suse.com/security/cve/CVE-2016-7412
- https://www.suse.com/security/cve/CVE-2016-7413
- https://www.suse.com/security/cve/CVE-2016-7414
- https://www.suse.com/security/cve/CVE-2016-7416
- https://www.suse.com/security/cve/CVE-2016-7417
- https://www.suse.com/security/cve/CVE-2016-7418
- https://www.suse.com/support/update/announcement/2016/suse-su-20162477-2/