Security update for php5
This update for php5 fixes the following issues: - CVE-2020-7064: Fixed a one byte read of uninitialized memory in exif_read_data() (bsc#1168326). - CVE-2020-7066: Fixed URL truncation get_headers() if the URL contains zero (\0) character (bsc#1168352). - CVE-2019-11048: Improved the handling of overly long filenames or field names in HTTP file uploads (bsc#1171999).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for php5 fixes the following issues: - CVE-2020-7064: Fixed a one byte read of uninitialized memory in exif_read_data() (bsc#1168326). - CVE-2020-7066: Fixed URL truncation get_headers() if the URL contains zero (\0) character (bsc#1168352). - CVE-2019-11048: Improved the handling of overly long filenames or field names in HTTP file uploads (bsc#1171999).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1168326
- https://bugzilla.suse.com/1168352
- https://bugzilla.suse.com/1171999
- https://www.suse.com/security/cve/CVE-2019-11048
- https://www.suse.com/security/cve/CVE-2020-7064
- https://www.suse.com/security/cve/CVE-2020-7066
- https://www.suse.com/support/update/announcement/2020/suse-su-20201714-1/