Fedora 21 : php-5.6.14-1.fc21 (2015-366f3dd73f)

high Nessus Plugin ID 89207

Synopsis

The remote Fedora host is missing a security update.

Description

01 Oct 2015, **PHP 5.6.14** **Core:** * Fixed bug php#70370 (Bundled libtool.m4 doesn't handle FreeBSD 10 when building extensions). (Adam)
**CLI server:** * Fixed bug php#68291 (404 on urls with '+'). (cmb)
**DOM:** * Fixed bug php#70001 (Assigning to DOMNode::textContent does additional entity encoding). (cmb) **Mysqlnd:** * Fixed bug php#70456 (mysqlnd doesn't activate TCP keep-alive when connecting to a server).
(Sergei Turchanov) **OpenSSL:** * Fixed bug php#55259 (openssl extension does not get the DH parameters from DH key resource). (Jakub Zelenka) * Fixed bug php#70395 (Missing ARG_INFO for openssl_seal()).
(cmb) * Fixed bug php#60632 (openssl_seal fails with AES). (Jakub Zelenka) * Fixed bug php#68312 (Lookup for openssl.cnf causes a message box). (Anatol) **PDO:** * Fixed bug php#70389 (PDO constructor changes unrelated variables). (Laruence) **Phar:** * Fixed bug php#69720 (NULL pointer dereference in phar_get_fp_offset()). (Stas) * Fixed bug php#70433 (Uninitialized pointer in phar_make_dirstream when zip entry filename is '/'). (Stas) **Phpdbg:** * Fix phpdbg_break_next() sometimes not breaking. (Bob) **Standard:** * Fixed bug php#67131 (setcookie() conditional for empty values not met). (cmb) **Streams:** * Fixed bug php#70361 (HTTP stream wrapper doesn't close keep-alive connections). (Niklas Keller)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected php package.

See Also

http://www.nessus.org/u?7916ee45

Plugin Details

Severity: High

ID: 89207

File Name: fedora_2015-366f3dd73f.nasl

Version: 2.3

Type: local

Agent: unix

Published: 3/4/2016

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php, cpe:/o:fedoraproject:fedora:21

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 10/13/2015

Reference Information