[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2020:1624-01 -- Redhat libzip, php, php-pear, php-pecl-apcu, php-pecl-zip

ID: oval:org.secpod.oval:def:69493Date: (C)2021-03-02   (M)2024-04-17
Class: PATCHFamily: unix




PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. The following packages have been upgraded to a later upstream version: php . Security Fix: * php: Invalid memory access in function xmlrpc_decode * php: File rename across filesystems may allow unwanted access during processing * php: Uninitialized read in exif_process_IFD_in_MAKERNOTE * php: Uninitialized read in exif_process_IFD_in_MAKERNOTE * php: Invalid read in exif_process_SOFn * php: Out-of-bounds read due to integer overflow in iconv_mime_decode_headers * php: Buffer over-read in exif_read_data * php: Buffer over-read in PHAR reading functions * php: Heap-based buffer over-read in PHAR reading functions * php: memcpy with negative length via crafted DNS response * php: Heap-based buffer over-read in mbstring regular expression functions * php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c * php: Heap buffer overflow in function exif_process_IFD_TAG * php: Heap buffer overflow in function exif_iif_add_value * php: Buffer over-read in exif_process_IFD_TAG leading to information disclosure * php: Heap buffer over-read in exif_scan_thumbnail * php: Heap buffer over-read in exif_process_user_comment For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the CentOS 8.2 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 8
Product:
libzip
php
php-pear
php-pecl-apcu
php-pecl-zip
Reference:
RHSA-2020:1624-01
CVE-2018-20783
CVE-2019-9020
CVE-2019-9021
CVE-2019-9022
CVE-2019-9023
CVE-2019-9024
CVE-2019-9637
CVE-2019-9638
CVE-2019-9639
CVE-2019-9640
CVE-2019-11034
CVE-2019-11035
CVE-2019-11036
CVE-2019-11039
CVE-2019-11040
CVE-2019-11041
CVE-2019-11042
CVE    17
CVE-2019-9639
CVE-2018-20783
CVE-2019-11042
CVE-2019-11040
...

© SecPod Technologies