SuSE 10 Security Update : PHP5 (ZYPP Patch Number 7553)

High Nessus Plugin ID 57158


The remote SuSE 10 host is missing a security-related patch.


This update for PHP5 fixes the following security issues :

- Input Validation in the ZIP extension and NumberFormatter. (CWE-20, CVE-2011-0421 / CVE-2011-1470 / CVE-2011-1467)

- Numeric Errors in the SHM support and ZIP extension.
(CWE-189, CVE-2011-1092 / CVE-2011-1471)

- Buffer overflows in the AF_UNIX support, string handling, streams support. (CWE-119, CVE-2011-1938 / CVE-2011-1464 / CVE-2011-1469)

- Resource management error (use after free) in string handling. (CWE-399, CVE-2011-1148)

- Memory leak in the OpenSSL extension (CVE-2011-1468)


Apply ZYPP patch number 7553.

See Also

Plugin Details

Severity: High

ID: 57158

File Name: suse_apache2-mod_php5-7553.nasl

Version: $Revision: 1.4 $

Type: local

Agent: unix

Published: 2011/12/13

Modified: 2016/12/22

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 2011/06/06

Reference Information

CVE: CVE-2011-0421, CVE-2011-1092, CVE-2011-1148, CVE-2011-1464, CVE-2011-1467, CVE-2011-1468, CVE-2011-1469, CVE-2011-1470, CVE-2011-1471, CVE-2011-1938

CWE: 20, 119, 189, 399