Fedora 28 : php (2019-efa799fd16)

high Nessus Plugin ID 122862

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

**PHP version 7.2.16** (07 Mar 2019)

**Core:**

- Fixed bug php#77589 (Core dump using parse_ini_string with numeric sections). (Laruence)

- Fixed bug php#77630 (rename() across the device may allow unwanted access during processing). (Stas)

**EXIF:**

- Fixed bug php#77509 (Uninitialized read in exif_process_IFD_in_TIFF). (Stas)

- Fixed bug php#77540 (Invalid Read on exif_process_SOFn).
(Stas)

- Fixed bug php#77563 (Uninitialized read in exif_process_IFD_in_MAKERNOTE). (Stas)

- Fixed bug php#77659 (Uninitialized read in exif_process_IFD_in_MAKERNOTE). (Stas)

**PHAR:**

- Fixed bug php#77396 (NULL pointer Dereference in phar_create_or_parse_filename). (bishop)

**SPL:**

- Fixed bug php#51068 (DirectoryIterator glob:// don't support current path relative queries). (Ahmed Abdou)

- Fixed bug php#77431 (openFile() silently truncates after a null byte). (cmb)

**Standard:**

- Fixed bug php#77552 (Unintialized php_stream_statbuf in stat functions). (John Stevenson)

**MySQL**

- Disabled LOCAL INFILE by default, can be enabled using php.ini directive mysqli.allow_local_infile for mysqli, or PDO::MYSQL_ATTR_LOCAL_INFILE attribute for pdo_mysql.
(Darek Slusarczyk)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected php package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2019-efa799fd16

Plugin Details

Severity: High

ID: 122862

File Name: fedora_2019-efa799fd16.nasl

Version: 1.2

Type: local

Agent: unix

Published: 3/15/2019

Updated: 9/23/2019

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php, cpe:/o:fedoraproject:fedora:28

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 3/15/2019

Vulnerability Publication Date: 3/15/2019

Reference Information