Fedora 29 : php (2019-aa6036fcb3)

high Nessus Plugin ID 121264

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

**PHP version 7.2.14** (10 Jan 2019)

**Core:**

- Fixed bug php#77369 (memcpy with negative length via crafted DNS response). (Stas)

- Fixed bug php#71041 (zend_signal_startup() needs ZEND_API). (Valentin V. Bartenev)

- Fixed bug php#76046 (PHP generates 'FE_FREE' opcode on the wrong line). (Nikita)

**Date:**

- Fixed bug php#77097 (DateTime::diff gives wrong diff when the actual diff is less than 1 second). (Derick)

**Exif:**

- Fixed bug php#77184 (Unsigned rational numbers are written out as signed rationals). (Colin Basnett)

**Opcache:**

- Fixed bug php#77215 (CFG assertion failure on multiple finalizing switch frees in one block). (Nikita)

**PDO:**

- Handle invalid index passed to PDOStatement::fetchColumn() as error. (Sergei Morozov)

**Phar:**

- Fixed bug php#77247 (heap buffer overflow in phar_detect_phar_fname_ext). (Stas)

**Sockets:**

- Fixed bug php#77136 (Unsupported IPV6_RECVPKTINFO constants on macOS). (Mizunashi Mana)

**SQLite3:**

- Fixed bug php#77051 (Issue with re-binding on SQLite3).
(BohwaZ)

**Xmlrpc:**

- Fixed bug php#77242 (heap out of bounds read in xmlrpc_decode()). (cmb)

- Fixed bug php#77380 (Global out of bounds read in xmlrpc base64 code). (Stas)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected php package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2019-aa6036fcb3

Plugin Details

Severity: High

ID: 121264

File Name: fedora_2019-aa6036fcb3.nasl

Version: 1.2

Type: local

Agent: unix

Published: 1/22/2019

Updated: 9/23/2019

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php, cpe:/o:fedoraproject:fedora:29

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 1/19/2019

Vulnerability Publication Date: 1/19/2019

Reference Information