Fedora 30 : php (2019-3f4ba94260)

high Nessus Plugin ID 124487

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

**PHP version 7.3.3** (07 Mar 2019)

**Core:**

- Fixed bug php#77589 (Core dump using parse_ini_string with numeric sections). (Laruence)

- Fixed bug php#77329 (Buffer Overflow via overly long Error Messages). (Dmitry)

- Fixed bug php#77494 (Disabling class causes segfault on member access). (Dmitry)

- Fixed bug php#77498 (Custom extension Segmentation fault when declare static property). (Nikita)

- Fixed bug php#77530 (PHP crashes when parsing `(2)::class`). (Ekin)

- Fixed bug php#77546 (iptcembed broken function).
(gdegoulet)

- Fixed bug php#77630 (rename() across the device may allow unwanted access during processing). (Stas)

**EXIF:**

- Fixed bug php#77509 (Uninitialized read in exif_process_IFD_in_TIFF). (Stas)

- Fixed bug php#77540 (Invalid Read on exif_process_SOFn).
(Stas)

- Fixed bug php#77563 (Uninitialized read in exif_process_IFD_in_MAKERNOTE). (Stas)

- Fixed bug php#77659 (Uninitialized read in exif_process_IFD_in_MAKERNOTE). (Stas)

**Mbstring:**

- Fixed bug php#77514 (mb_ereg_replace() with trailing backslash adds null byte). (Nikita)

**MySQL**

- Disabled LOCAL INFILE by default, can be enabled using php.ini directive mysqli.allow_local_infile for mysqli, or PDO::MYSQL_ATTR_LOCAL_INFILE attribute for pdo_mysql.
(Darek Slusarczyk)

**OpenSSL:**

- Fixed bug php#77390 (feof might hang on TLS streams in case of fragmented TLS records). (Abyl Valg, Jakub Zelenka)

**PHAR:**

- Fixed bug php#77396 (NULL pointer Dereference in phar_create_or_parse_filename). (bishop)

- Fixed bug php#77586 (phar_tar_writeheaders_int() buffer overflow). (bishop)

**phpdbg:**

- Fixed bug php#76596 (phpdbg support for display_errors=stderr). (kabel)

**SPL:**

- Fixed bug php#51068 (DirectoryIterator glob:// don't support current path relative queries). (Ahmed Abdou)

- Fixed bug php#77431 (openFile() silently truncates after a null byte). (cmb)

**Standard:**

- Fixed bug php#77552 (Unintialized php_stream_statbuf in stat functions). (John Stevenson)

- Fixed bug php#77612 (setcookie() sets incorrect SameSite header if all of its options filled). (Nikita)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected php package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2019-3f4ba94260

Plugin Details

Severity: High

ID: 124487

File Name: fedora_2019-3f4ba94260.nasl

Version: 1.2

Type: local

Agent: unix

Published: 5/2/2019

Updated: 9/23/2019

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:php, cpe:/o:fedoraproject:fedora:30

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 3/29/2019

Vulnerability Publication Date: 3/29/2019

Reference Information