Fedora 28 : php (2019-253da50ddd)

High Nessus Plugin ID 124040

Synopsis

The remote Fedora host is missing a security update.

Description

**PHP version 7.2.17** (04 Apr 2019)

**Core:**

- Fixed bug php#77738 (Nullptr deref in zend_compile_expr). (Laruence)

- Fixed bug php#77660 (Segmentation fault on break 2147483648). (Laruence)

- Fixed bug php#77652 (Anonymous classes can lose their interface information). (Nikita)

- Fixed bug php#77676 (Unable to run tests when building shared extension on AIX). (Kevin Adler)

**Bcmath:**

- Fixed bug php#77742 (bcpow() implementation related to gcc compiler optimization). (Nikita)

**COM:**

- Fixed bug php#77578 (Crash when php unload). (cmb)

**Date:**

- Fixed bug php#50020 (DateInterval:createDateFromString() silently fails). (Derick)

- Fixed bug php#75113 (Added DatePeriod::getRecurrences() method). (Ignace Nyamagana Butera)

**EXIF:**

- Fixed bug php#77753 (Heap-buffer-overflow in php_ifd_get32s). (Stas)

- Fixed bug php#77831 (Heap-buffer-overflow in exif_iif_add_value). (Stas)

**FPM:**

- Fixed bug php#77677 (FPM fails to build on AIX due to missing WCOREDUMP). (Kevin Adler)

**GD:**

- Fixed bug php#77700 (Writing truecolor images as GIF ignores interlace flag). (cmb)

**MySQLi:**

- Fixed bug php#77597 (mysqli_fetch_field hangs scripts).
(Nikita)

**Opcache:**

- Fixed bug php#77691 (Opcache passes wrong value for inline array push assignments). (Nikita)

- Fixed bug php#77743 (Incorrect pi node insertion for jmpznz with identical successors). (Nikita)

**phpdbg:**

- Fixed bug php#77767 (phpdbg break cmd aliases listed in help do not match actual aliases). (Miriam Lauter)

**sodium:**

- Fixed bug php#77646 (sign_detached() strings not terminated). (Frank)

**SQLite3:**

- Added sqlite3.defensive INI directive. (BohwaZ)

**Standard:**

- Fixed bug php#77664 (Segmentation fault when using undefined constant in custom wrapper). (Laruence)

- Fixed bug php#77669 (Crash in extract() when overwriting extracted array). (Nikita)

- Fixed bug php#76717 (var_export() does not create a parsable value for PHP_INT_MIN). (Nikita)

- Fixed bug php#77765 (FTP stream wrapper should set the directory as executable). (Vlad Temian)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected php package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2019-253da50ddd

Plugin Details

Severity: High

ID: 124040

File Name: fedora_2019-253da50ddd.nasl

Version: 1.1

Type: local

Agent: unix

Published: 2019/04/15

Updated: 2019/04/15

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php, cpe:/o:fedoraproject:fedora:28

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 2019/04/13

Vulnerability Publication Date: 2019/04/13

Reference Information