openSUSE Security Update : php / php5 / php53 (openSUSE-SU-2014:0925-1)

High Nessus Plugin ID 76722

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 5.9

Synopsis

The remote openSUSE host is missing a security update.

Description

This update fixes the following security issues with php, php5 and php53 :

- bnc#884986, CVE-2014-0207: file: php5:
cdf_read_short_sector insufficient boundary check

- bnc#884987, CVE-2014-3478: file: mconvert incorrect handling of truncated pascal string size

- bnc#884989, CVE-2014-3479: php53: file:
cdf_check_stream_offset insufficient boundary check

- bnc#884990, CVE-2014-3480: php53: file: cdf_count_chain insufficient boundary check

- bnc#884991, CVE-2014-3487: php53: file:
cdf_read_property_info insufficient boundary check

- bnc#884992, CVE-2014-3515: php5: unserialize() SPL ArrayObject / SPLObjectStorage Type Confusion

Solution

Update the affected php / php5 / php53 packages.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=884986

https://bugzilla.novell.com/show_bug.cgi?id=884987

https://bugzilla.novell.com/show_bug.cgi?id=884989

https://bugzilla.novell.com/show_bug.cgi?id=884990

https://bugzilla.novell.com/show_bug.cgi?id=884991

https://bugzilla.novell.com/show_bug.cgi?id=884992

https://lists.opensuse.org/opensuse-updates/2014-07/msg00026.html

Plugin Details

Severity: High

ID: 76722

File Name: openSUSE-2014-464.nasl

Version: 1.6

Type: local

Agent: unix

Published: 2014/07/24

Updated: 2020/06/04

Dependencies: 12634

Risk Information

Risk Factor: High

VPR Score: 5.9

CVSS v2.0

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:apache2-mod_php5, p-cpe:/a:novell:opensuse:apache2-mod_php5-debuginfo, p-cpe:/a:novell:opensuse:php5, p-cpe:/a:novell:opensuse:php5-bcmath, p-cpe:/a:novell:opensuse:php5-bcmath-debuginfo, p-cpe:/a:novell:opensuse:php5-bz2, p-cpe:/a:novell:opensuse:php5-bz2-debuginfo, p-cpe:/a:novell:opensuse:php5-calendar, p-cpe:/a:novell:opensuse:php5-calendar-debuginfo, p-cpe:/a:novell:opensuse:php5-ctype, p-cpe:/a:novell:opensuse:php5-ctype-debuginfo, p-cpe:/a:novell:opensuse:php5-curl, p-cpe:/a:novell:opensuse:php5-curl-debuginfo, p-cpe:/a:novell:opensuse:php5-dba, p-cpe:/a:novell:opensuse:php5-dba-debuginfo, p-cpe:/a:novell:opensuse:php5-debuginfo, p-cpe:/a:novell:opensuse:php5-debugsource, p-cpe:/a:novell:opensuse:php5-devel, p-cpe:/a:novell:opensuse:php5-dom, p-cpe:/a:novell:opensuse:php5-dom-debuginfo, p-cpe:/a:novell:opensuse:php5-enchant, p-cpe:/a:novell:opensuse:php5-enchant-debuginfo, p-cpe:/a:novell:opensuse:php5-exif, p-cpe:/a:novell:opensuse:php5-exif-debuginfo, p-cpe:/a:novell:opensuse:php5-fastcgi, p-cpe:/a:novell:opensuse:php5-fastcgi-debuginfo, p-cpe:/a:novell:opensuse:php5-fileinfo, p-cpe:/a:novell:opensuse:php5-fileinfo-debuginfo, p-cpe:/a:novell:opensuse:php5-firebird, p-cpe:/a:novell:opensuse:php5-firebird-debuginfo, p-cpe:/a:novell:opensuse:php5-fpm, p-cpe:/a:novell:opensuse:php5-fpm-debuginfo, p-cpe:/a:novell:opensuse:php5-ftp, p-cpe:/a:novell:opensuse:php5-ftp-debuginfo, p-cpe:/a:novell:opensuse:php5-gd, p-cpe:/a:novell:opensuse:php5-gd-debuginfo, p-cpe:/a:novell:opensuse:php5-gettext, p-cpe:/a:novell:opensuse:php5-gettext-debuginfo, p-cpe:/a:novell:opensuse:php5-gmp, p-cpe:/a:novell:opensuse:php5-gmp-debuginfo, p-cpe:/a:novell:opensuse:php5-iconv, p-cpe:/a:novell:opensuse:php5-iconv-debuginfo, p-cpe:/a:novell:opensuse:php5-imap, p-cpe:/a:novell:opensuse:php5-imap-debuginfo, p-cpe:/a:novell:opensuse:php5-intl, p-cpe:/a:novell:opensuse:php5-intl-debuginfo, p-cpe:/a:novell:opensuse:php5-json, p-cpe:/a:novell:opensuse:php5-json-debuginfo, p-cpe:/a:novell:opensuse:php5-ldap, p-cpe:/a:novell:opensuse:php5-ldap-debuginfo, p-cpe:/a:novell:opensuse:php5-mbstring, p-cpe:/a:novell:opensuse:php5-mbstring-debuginfo, p-cpe:/a:novell:opensuse:php5-mcrypt, p-cpe:/a:novell:opensuse:php5-mcrypt-debuginfo, p-cpe:/a:novell:opensuse:php5-mssql, p-cpe:/a:novell:opensuse:php5-mssql-debuginfo, p-cpe:/a:novell:opensuse:php5-mysql, p-cpe:/a:novell:opensuse:php5-mysql-debuginfo, p-cpe:/a:novell:opensuse:php5-odbc, p-cpe:/a:novell:opensuse:php5-odbc-debuginfo, p-cpe:/a:novell:opensuse:php5-openssl, p-cpe:/a:novell:opensuse:php5-openssl-debuginfo, p-cpe:/a:novell:opensuse:php5-pcntl, p-cpe:/a:novell:opensuse:php5-pcntl-debuginfo, p-cpe:/a:novell:opensuse:php5-pdo, p-cpe:/a:novell:opensuse:php5-pdo-debuginfo, p-cpe:/a:novell:opensuse:php5-pear, p-cpe:/a:novell:opensuse:php5-pgsql, p-cpe:/a:novell:opensuse:php5-pgsql-debuginfo, p-cpe:/a:novell:opensuse:php5-phar, p-cpe:/a:novell:opensuse:php5-phar-debuginfo, p-cpe:/a:novell:opensuse:php5-posix, p-cpe:/a:novell:opensuse:php5-posix-debuginfo, p-cpe:/a:novell:opensuse:php5-pspell, p-cpe:/a:novell:opensuse:php5-pspell-debuginfo, p-cpe:/a:novell:opensuse:php5-readline, p-cpe:/a:novell:opensuse:php5-readline-debuginfo, p-cpe:/a:novell:opensuse:php5-shmop, p-cpe:/a:novell:opensuse:php5-shmop-debuginfo, p-cpe:/a:novell:opensuse:php5-snmp, p-cpe:/a:novell:opensuse:php5-snmp-debuginfo, p-cpe:/a:novell:opensuse:php5-soap, p-cpe:/a:novell:opensuse:php5-soap-debuginfo, p-cpe:/a:novell:opensuse:php5-sockets, p-cpe:/a:novell:opensuse:php5-sockets-debuginfo, p-cpe:/a:novell:opensuse:php5-sqlite, p-cpe:/a:novell:opensuse:php5-sqlite-debuginfo, p-cpe:/a:novell:opensuse:php5-suhosin, p-cpe:/a:novell:opensuse:php5-suhosin-debuginfo, p-cpe:/a:novell:opensuse:php5-sysvmsg, p-cpe:/a:novell:opensuse:php5-sysvmsg-debuginfo, p-cpe:/a:novell:opensuse:php5-sysvsem, p-cpe:/a:novell:opensuse:php5-sysvsem-debuginfo, p-cpe:/a:novell:opensuse:php5-sysvshm, p-cpe:/a:novell:opensuse:php5-sysvshm-debuginfo, p-cpe:/a:novell:opensuse:php5-tidy, p-cpe:/a:novell:opensuse:php5-tidy-debuginfo, p-cpe:/a:novell:opensuse:php5-tokenizer, p-cpe:/a:novell:opensuse:php5-tokenizer-debuginfo, p-cpe:/a:novell:opensuse:php5-wddx, p-cpe:/a:novell:opensuse:php5-wddx-debuginfo, p-cpe:/a:novell:opensuse:php5-xmlreader, p-cpe:/a:novell:opensuse:php5-xmlreader-debuginfo, p-cpe:/a:novell:opensuse:php5-xmlrpc, p-cpe:/a:novell:opensuse:php5-xmlrpc-debuginfo, p-cpe:/a:novell:opensuse:php5-xmlwriter, p-cpe:/a:novell:opensuse:php5-xmlwriter-debuginfo, p-cpe:/a:novell:opensuse:php5-xsl, p-cpe:/a:novell:opensuse:php5-xsl-debuginfo, p-cpe:/a:novell:opensuse:php5-zip, p-cpe:/a:novell:opensuse:php5-zip-debuginfo, p-cpe:/a:novell:opensuse:php5-zlib, p-cpe:/a:novell:opensuse:php5-zlib-debuginfo, cpe:/o:novell:opensuse:12.3, cpe:/o:novell:opensuse:13.1

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2014/07/10

Reference Information

CVE: CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487, CVE-2014-3515