SUSE-SU-2019:0988-1

Source
https://www.suse.com/support/update/announcement/2019/suse-su-20190988-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:0988-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2019:0988-1
Related
Published
2019-04-23T06:46:19Z
Modified
2019-04-23T06:46:19Z
Summary
Security update for php72
Details

This update for php72 fixes the following issues:

  • CVE-2019-9637: Due to the way rename() across filesystems is implemented, it was possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data. (bsc#1128892)
  • CVE-2019-9675: phartarwriteheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: 'This issue allows theoretical compromise of security, but a practical attack is usually impossible.' (bsc#1128886)
  • CVE-2019-9638: An issue was discovered in the EXIF component in PHP. There was an uninitialized read in exifprocessIFDinMAKERNOTE because of mishandling the makernote->offset relationship to valuelen. (bsc#1128889)
  • CVE-2019-9639: An issue was discovered in the EXIF component in PHP. There was an uninitialized read in exifprocessIFDinMAKERNOTE because of mishandling the data_len variable. (bsc#1128887)
  • CVE-2019-9640: An issue was discovered in the EXIF component in PHP. There was an Invalid Read in exifprocessSOFn. (bsc#1128883)
References

Affected packages

SUSE:Linux Enterprise Module for Web and Scripting 12 / php72

Package

Name
php72
Purl
pkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.5-1.10.1

Ecosystem specific

{
    "binaries": [
        {
            "php72-curl": "7.2.5-1.10.1",
            "php72-ftp": "7.2.5-1.10.1",
            "php72-json": "7.2.5-1.10.1",
            "php72-intl": "7.2.5-1.10.1",
            "php72-imap": "7.2.5-1.10.1",
            "php72-xmlwriter": "7.2.5-1.10.1",
            "php72-tokenizer": "7.2.5-1.10.1",
            "php72-odbc": "7.2.5-1.10.1",
            "php72-zip": "7.2.5-1.10.1",
            "php72-shmop": "7.2.5-1.10.1",
            "php72-openssl": "7.2.5-1.10.1",
            "php72-tidy": "7.2.5-1.10.1",
            "php72-pspell": "7.2.5-1.10.1",
            "apache2-mod_php72": "7.2.5-1.10.1",
            "php72-ctype": "7.2.5-1.10.1",
            "php72-gmp": "7.2.5-1.10.1",
            "php72-gettext": "7.2.5-1.10.1",
            "php72-sqlite": "7.2.5-1.10.1",
            "php72-xmlreader": "7.2.5-1.10.1",
            "php72-pgsql": "7.2.5-1.10.1",
            "php72-ldap": "7.2.5-1.10.1",
            "php72-sysvmsg": "7.2.5-1.10.1",
            "php72-gd": "7.2.5-1.10.1",
            "php72-mysql": "7.2.5-1.10.1",
            "php72-pear-Archive_Tar": "7.2.5-1.10.1",
            "php72-calendar": "7.2.5-1.10.1",
            "php72-iconv": "7.2.5-1.10.1",
            "php72-fastcgi": "7.2.5-1.10.1",
            "php72-enchant": "7.2.5-1.10.1",
            "php72-dom": "7.2.5-1.10.1",
            "php72-phar": "7.2.5-1.10.1",
            "php72-sockets": "7.2.5-1.10.1",
            "php72-mbstring": "7.2.5-1.10.1",
            "php72-wddx": "7.2.5-1.10.1",
            "php72-pcntl": "7.2.5-1.10.1",
            "php72-fpm": "7.2.5-1.10.1",
            "php72-sysvshm": "7.2.5-1.10.1",
            "php72-fileinfo": "7.2.5-1.10.1",
            "php72-dba": "7.2.5-1.10.1",
            "php72-pdo": "7.2.5-1.10.1",
            "php72-sysvsem": "7.2.5-1.10.1",
            "php72-pear": "7.2.5-1.10.1",
            "php72-bcmath": "7.2.5-1.10.1",
            "php72-posix": "7.2.5-1.10.1",
            "php72-bz2": "7.2.5-1.10.1",
            "php72-readline": "7.2.5-1.10.1",
            "php72-soap": "7.2.5-1.10.1",
            "php72-xsl": "7.2.5-1.10.1",
            "php72-exif": "7.2.5-1.10.1",
            "php72-zlib": "7.2.5-1.10.1",
            "php72": "7.2.5-1.10.1",
            "php72-opcache": "7.2.5-1.10.1",
            "php72-xmlrpc": "7.2.5-1.10.1",
            "php72-snmp": "7.2.5-1.10.1"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 SP3 / php72

Package

Name
php72
Purl
pkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.5-1.10.1

Ecosystem specific

{
    "binaries": [
        {
            "php72-devel": "7.2.5-1.10.1"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 SP4 / php72

Package

Name
php72
Purl
pkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.5-1.10.1

Ecosystem specific

{
    "binaries": [
        {
            "php72-devel": "7.2.5-1.10.1"
        }
    ]
}