<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">php8-8.0.11-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:11169</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-17T21:45:33Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-17T21:45:33Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-17T21:45:33Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">php8-8.0.11-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the php8-8.0.11-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-11169</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL/>
      <Description>E-Mail link for openSUSE-SU-2024:11169</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2005-3353/</URL>
      <Description>SUSE CVE CVE-2005-3353 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2005-3388/</URL>
      <Description>SUSE CVE CVE-2005-3388 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2005-3389/</URL>
      <Description>SUSE CVE CVE-2005-3389 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2005-3390/</URL>
      <Description>SUSE CVE CVE-2005-3390 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2005-3391/</URL>
      <Description>SUSE CVE CVE-2005-3391 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2005-3392/</URL>
      <Description>SUSE CVE CVE-2005-3392 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-0996/</URL>
      <Description>SUSE CVE CVE-2006-0996 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-1017/</URL>
      <Description>SUSE CVE CVE-2006-1017 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-1490/</URL>
      <Description>SUSE CVE CVE-2006-1490 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-1494/</URL>
      <Description>SUSE CVE CVE-2006-1494 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-1991/</URL>
      <Description>SUSE CVE CVE-2006-1991 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-7243/</URL>
      <Description>SUSE CVE CVE-2006-7243 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2007-4783/</URL>
      <Description>SUSE CVE CVE-2007-4783 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2007-4887/</URL>
      <Description>SUSE CVE CVE-2007-4887 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2008-0599/</URL>
      <Description>SUSE CVE CVE-2008-0599 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-2225/</URL>
      <Description>SUSE CVE CVE-2010-2225 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-2950/</URL>
      <Description>SUSE CVE CVE-2010-2950 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-3436/</URL>
      <Description>SUSE CVE CVE-2010-3436 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-3709/</URL>
      <Description>SUSE CVE CVE-2010-3709 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-3710/</URL>
      <Description>SUSE CVE CVE-2010-3710 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-4150/</URL>
      <Description>SUSE CVE CVE-2010-4150 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-4645/</URL>
      <Description>SUSE CVE CVE-2010-4645 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-0420/</URL>
      <Description>SUSE CVE CVE-2011-0420 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-0421/</URL>
      <Description>SUSE CVE CVE-2011-0421 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-0708/</URL>
      <Description>SUSE CVE CVE-2011-0708 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-1092/</URL>
      <Description>SUSE CVE CVE-2011-1092 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-1153/</URL>
      <Description>SUSE CVE CVE-2011-1153 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-1466/</URL>
      <Description>SUSE CVE CVE-2011-1466 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-2202/</URL>
      <Description>SUSE CVE CVE-2011-2202 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-3379/</URL>
      <Description>SUSE CVE CVE-2011-3379 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-4153/</URL>
      <Description>SUSE CVE CVE-2011-4153 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-4566/</URL>
      <Description>SUSE CVE CVE-2011-4566 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2011-4885/</URL>
      <Description>SUSE CVE CVE-2011-4885 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-0830/</URL>
      <Description>SUSE CVE CVE-2012-0830 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-1823/</URL>
      <Description>SUSE CVE CVE-2012-1823 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-2688/</URL>
      <Description>SUSE CVE CVE-2012-2688 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-3365/</URL>
      <Description>SUSE CVE CVE-2012-3365 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-1635/</URL>
      <Description>SUSE CVE CVE-2013-1635 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-1643/</URL>
      <Description>SUSE CVE CVE-2013-1643 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4113/</URL>
      <Description>SUSE CVE CVE-2013-4113 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-4248/</URL>
      <Description>SUSE CVE CVE-2013-4248 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-6420/</URL>
      <Description>SUSE CVE CVE-2013-6420 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-6712/</URL>
      <Description>SUSE CVE CVE-2013-6712 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-7327/</URL>
      <Description>SUSE CVE CVE-2013-7327 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-7345/</URL>
      <Description>SUSE CVE CVE-2013-7345 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0185/</URL>
      <Description>SUSE CVE CVE-2014-0185 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0238/</URL>
      <Description>SUSE CVE CVE-2014-0238 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-1943/</URL>
      <Description>SUSE CVE CVE-2014-1943 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-2497/</URL>
      <Description>SUSE CVE CVE-2014-2497 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3538/</URL>
      <Description>SUSE CVE CVE-2014-3538 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3597/</URL>
      <Description>SUSE CVE CVE-2014-3597 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3622/</URL>
      <Description>SUSE CVE CVE-2014-3622 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3668/</URL>
      <Description>SUSE CVE CVE-2014-3668 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3670/</URL>
      <Description>SUSE CVE CVE-2014-3670 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4049/</URL>
      <Description>SUSE CVE CVE-2014-4049 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4670/</URL>
      <Description>SUSE CVE CVE-2014-4670 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4698/</URL>
      <Description>SUSE CVE CVE-2014-4698 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-5459/</URL>
      <Description>SUSE CVE CVE-2014-5459 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-9426/</URL>
      <Description>SUSE CVE CVE-2014-9426 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-9427/</URL>
      <Description>SUSE CVE CVE-2014-9427 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0231/</URL>
      <Description>SUSE CVE CVE-2015-0231 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0235/</URL>
      <Description>SUSE CVE CVE-2015-0235 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0273/</URL>
      <Description>SUSE CVE CVE-2015-0273 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-1351/</URL>
      <Description>SUSE CVE CVE-2015-1351 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3152/</URL>
      <Description>SUSE CVE CVE-2015-3152 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3414/</URL>
      <Description>SUSE CVE CVE-2015-3414 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-3415/</URL>
      <Description>SUSE CVE CVE-2015-3415 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-9120/</URL>
      <Description>SUSE CVE CVE-2017-9120 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-1000222/</URL>
      <Description>SUSE CVE CVE-2018-1000222 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-1000888/</URL>
      <Description>SUSE CVE CVE-2018-1000888 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-12882/</URL>
      <Description>SUSE CVE CVE-2018-12882 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-14851/</URL>
      <Description>SUSE CVE CVE-2018-14851 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-17082/</URL>
      <Description>SUSE CVE CVE-2018-17082 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-19935/</URL>
      <Description>SUSE CVE CVE-2018-19935 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-20783/</URL>
      <Description>SUSE CVE CVE-2018-20783 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11034/</URL>
      <Description>SUSE CVE CVE-2019-11034 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11035/</URL>
      <Description>SUSE CVE CVE-2019-11035 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11036/</URL>
      <Description>SUSE CVE CVE-2019-11036 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11039/</URL>
      <Description>SUSE CVE CVE-2019-11039 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11040/</URL>
      <Description>SUSE CVE CVE-2019-11040 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11041/</URL>
      <Description>SUSE CVE CVE-2019-11041 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11042/</URL>
      <Description>SUSE CVE CVE-2019-11042 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11043/</URL>
      <Description>SUSE CVE CVE-2019-11043 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-11046/</URL>
      <Description>SUSE CVE CVE-2019-11046 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9020/</URL>
      <Description>SUSE CVE CVE-2019-9020 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9021/</URL>
      <Description>SUSE CVE CVE-2019-9021 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9022/</URL>
      <Description>SUSE CVE CVE-2019-9022 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9023/</URL>
      <Description>SUSE CVE CVE-2019-9023 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9024/</URL>
      <Description>SUSE CVE CVE-2019-9024 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9637/</URL>
      <Description>SUSE CVE CVE-2019-9637 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9638/</URL>
      <Description>SUSE CVE CVE-2019-9638 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9640/</URL>
      <Description>SUSE CVE CVE-2019-9640 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9641/</URL>
      <Description>SUSE CVE CVE-2019-9641 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-9675/</URL>
      <Description>SUSE CVE CVE-2019-9675 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-7062/</URL>
      <Description>SUSE CVE CVE-2020-7062 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-7063/</URL>
      <Description>SUSE CVE CVE-2020-7063 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21706/</URL>
      <Description>SUSE CVE CVE-2021-21706 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="php8-8.0.11-1.1">
      <FullProductName ProductID="php8-8.0.11-1.1">php8-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-bcmath-8.0.11-1.1">
      <FullProductName ProductID="php8-bcmath-8.0.11-1.1">php8-bcmath-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-bz2-8.0.11-1.1">
      <FullProductName ProductID="php8-bz2-8.0.11-1.1">php8-bz2-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-calendar-8.0.11-1.1">
      <FullProductName ProductID="php8-calendar-8.0.11-1.1">php8-calendar-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-cli-8.0.11-1.1">
      <FullProductName ProductID="php8-cli-8.0.11-1.1">php8-cli-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-ctype-8.0.11-1.1">
      <FullProductName ProductID="php8-ctype-8.0.11-1.1">php8-ctype-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-curl-8.0.11-1.1">
      <FullProductName ProductID="php8-curl-8.0.11-1.1">php8-curl-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-dba-8.0.11-1.1">
      <FullProductName ProductID="php8-dba-8.0.11-1.1">php8-dba-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-devel-8.0.11-1.1">
      <FullProductName ProductID="php8-devel-8.0.11-1.1">php8-devel-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-dom-8.0.11-1.1">
      <FullProductName ProductID="php8-dom-8.0.11-1.1">php8-dom-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-enchant-8.0.11-1.1">
      <FullProductName ProductID="php8-enchant-8.0.11-1.1">php8-enchant-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-exif-8.0.11-1.1">
      <FullProductName ProductID="php8-exif-8.0.11-1.1">php8-exif-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-fileinfo-8.0.11-1.1">
      <FullProductName ProductID="php8-fileinfo-8.0.11-1.1">php8-fileinfo-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-ftp-8.0.11-1.1">
      <FullProductName ProductID="php8-ftp-8.0.11-1.1">php8-ftp-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-gd-8.0.11-1.1">
      <FullProductName ProductID="php8-gd-8.0.11-1.1">php8-gd-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-gettext-8.0.11-1.1">
      <FullProductName ProductID="php8-gettext-8.0.11-1.1">php8-gettext-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-gmp-8.0.11-1.1">
      <FullProductName ProductID="php8-gmp-8.0.11-1.1">php8-gmp-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-iconv-8.0.11-1.1">
      <FullProductName ProductID="php8-iconv-8.0.11-1.1">php8-iconv-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-intl-8.0.11-1.1">
      <FullProductName ProductID="php8-intl-8.0.11-1.1">php8-intl-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-ldap-8.0.11-1.1">
      <FullProductName ProductID="php8-ldap-8.0.11-1.1">php8-ldap-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-mbstring-8.0.11-1.1">
      <FullProductName ProductID="php8-mbstring-8.0.11-1.1">php8-mbstring-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-mysql-8.0.11-1.1">
      <FullProductName ProductID="php8-mysql-8.0.11-1.1">php8-mysql-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-odbc-8.0.11-1.1">
      <FullProductName ProductID="php8-odbc-8.0.11-1.1">php8-odbc-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-opcache-8.0.11-1.1">
      <FullProductName ProductID="php8-opcache-8.0.11-1.1">php8-opcache-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-openssl-8.0.11-1.1">
      <FullProductName ProductID="php8-openssl-8.0.11-1.1">php8-openssl-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-pcntl-8.0.11-1.1">
      <FullProductName ProductID="php8-pcntl-8.0.11-1.1">php8-pcntl-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-pdo-8.0.11-1.1">
      <FullProductName ProductID="php8-pdo-8.0.11-1.1">php8-pdo-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-pgsql-8.0.11-1.1">
      <FullProductName ProductID="php8-pgsql-8.0.11-1.1">php8-pgsql-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-phar-8.0.11-1.1">
      <FullProductName ProductID="php8-phar-8.0.11-1.1">php8-phar-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-posix-8.0.11-1.1">
      <FullProductName ProductID="php8-posix-8.0.11-1.1">php8-posix-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-readline-8.0.11-1.1">
      <FullProductName ProductID="php8-readline-8.0.11-1.1">php8-readline-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-shmop-8.0.11-1.1">
      <FullProductName ProductID="php8-shmop-8.0.11-1.1">php8-shmop-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-snmp-8.0.11-1.1">
      <FullProductName ProductID="php8-snmp-8.0.11-1.1">php8-snmp-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-soap-8.0.11-1.1">
      <FullProductName ProductID="php8-soap-8.0.11-1.1">php8-soap-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sockets-8.0.11-1.1">
      <FullProductName ProductID="php8-sockets-8.0.11-1.1">php8-sockets-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sodium-8.0.11-1.1">
      <FullProductName ProductID="php8-sodium-8.0.11-1.1">php8-sodium-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sqlite-8.0.11-1.1">
      <FullProductName ProductID="php8-sqlite-8.0.11-1.1">php8-sqlite-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sysvmsg-8.0.11-1.1">
      <FullProductName ProductID="php8-sysvmsg-8.0.11-1.1">php8-sysvmsg-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sysvsem-8.0.11-1.1">
      <FullProductName ProductID="php8-sysvsem-8.0.11-1.1">php8-sysvsem-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-sysvshm-8.0.11-1.1">
      <FullProductName ProductID="php8-sysvshm-8.0.11-1.1">php8-sysvshm-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-tidy-8.0.11-1.1">
      <FullProductName ProductID="php8-tidy-8.0.11-1.1">php8-tidy-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-tokenizer-8.0.11-1.1">
      <FullProductName ProductID="php8-tokenizer-8.0.11-1.1">php8-tokenizer-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-xmlreader-8.0.11-1.1">
      <FullProductName ProductID="php8-xmlreader-8.0.11-1.1">php8-xmlreader-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-xmlwriter-8.0.11-1.1">
      <FullProductName ProductID="php8-xmlwriter-8.0.11-1.1">php8-xmlwriter-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-xsl-8.0.11-1.1">
      <FullProductName ProductID="php8-xsl-8.0.11-1.1">php8-xsl-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-zip-8.0.11-1.1">
      <FullProductName ProductID="php8-zip-8.0.11-1.1">php8-zip-8.0.11-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="php8-zlib-8.0.11-1.1">
      <FullProductName ProductID="php8-zlib-8.0.11-1.1">php8-zlib-8.0.11-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="php8-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-8.0.11-1.1">php8-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-bcmath-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1">php8-bcmath-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-bz2-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-bz2-8.0.11-1.1">php8-bz2-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-calendar-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-calendar-8.0.11-1.1">php8-calendar-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-cli-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-cli-8.0.11-1.1">php8-cli-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-ctype-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-ctype-8.0.11-1.1">php8-ctype-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-curl-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-curl-8.0.11-1.1">php8-curl-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-dba-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-dba-8.0.11-1.1">php8-dba-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-devel-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-devel-8.0.11-1.1">php8-devel-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-dom-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-dom-8.0.11-1.1">php8-dom-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-enchant-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-enchant-8.0.11-1.1">php8-enchant-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-exif-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-exif-8.0.11-1.1">php8-exif-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-fileinfo-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1">php8-fileinfo-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-ftp-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-ftp-8.0.11-1.1">php8-ftp-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-gd-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-gd-8.0.11-1.1">php8-gd-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-gettext-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-gettext-8.0.11-1.1">php8-gettext-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-gmp-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-gmp-8.0.11-1.1">php8-gmp-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-iconv-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-iconv-8.0.11-1.1">php8-iconv-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-intl-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-intl-8.0.11-1.1">php8-intl-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-ldap-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-ldap-8.0.11-1.1">php8-ldap-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-mbstring-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1">php8-mbstring-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-mysql-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-mysql-8.0.11-1.1">php8-mysql-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-odbc-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-odbc-8.0.11-1.1">php8-odbc-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-opcache-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-opcache-8.0.11-1.1">php8-opcache-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-openssl-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-openssl-8.0.11-1.1">php8-openssl-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-pcntl-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1">php8-pcntl-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-pdo-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-pdo-8.0.11-1.1">php8-pdo-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-pgsql-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1">php8-pgsql-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-phar-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-phar-8.0.11-1.1">php8-phar-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-posix-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-posix-8.0.11-1.1">php8-posix-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-readline-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-readline-8.0.11-1.1">php8-readline-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-shmop-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-shmop-8.0.11-1.1">php8-shmop-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-snmp-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-snmp-8.0.11-1.1">php8-snmp-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-soap-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-soap-8.0.11-1.1">php8-soap-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sockets-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sockets-8.0.11-1.1">php8-sockets-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sodium-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sodium-8.0.11-1.1">php8-sodium-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sqlite-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1">php8-sqlite-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sysvmsg-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1">php8-sysvmsg-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sysvsem-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1">php8-sysvsem-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-sysvshm-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1">php8-sysvshm-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-tidy-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-tidy-8.0.11-1.1">php8-tidy-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-tokenizer-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1">php8-tokenizer-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-xmlreader-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1">php8-xmlreader-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-xmlwriter-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1">php8-xmlwriter-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-xsl-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-xsl-8.0.11-1.1">php8-xsl-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-zip-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-zip-8.0.11-1.1">php8-zip-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="php8-zlib-8.0.11-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:php8-zlib-8.0.11-1.1">php8-zlib-8.0.11-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The exif_read_data function in the Exif module in PHP before 4.4.1 allows remote attackers to cause a denial of service (infinite loop) via a malformed JPEG image.</Note>
    </Notes>
    <CVE>CVE-2005-3353</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2005-3353.html</URL>
        <Description>CVE-2005-3353</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/118976</URL>
        <Description>SUSE Bug 118976</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/120087</URL>
        <Description>SUSE Bug 120087</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/130227</URL>
        <Description>SUSE Bug 130227</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131578</URL>
        <Description>SUSE Bug 131578</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131579</URL>
        <Description>SUSE Bug 131579</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131580</URL>
        <Description>SUSE Bug 131580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/132684</URL>
        <Description>SUSE Bug 132684</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/135480</URL>
        <Description>SUSE Bug 135480</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/529198</URL>
        <Description>SUSE Bug 529198</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."</Note>
    </Notes>
    <CVE>CVE-2005-3388</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2005-3388.html</URL>
        <Description>CVE-2005-3388</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/120087</URL>
        <Description>SUSE Bug 120087</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131578</URL>
        <Description>SUSE Bug 131578</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131579</URL>
        <Description>SUSE Bug 131579</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131580</URL>
        <Description>SUSE Bug 131580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/132684</URL>
        <Description>SUSE Bug 132684</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.</Note>
    </Notes>
    <CVE>CVE-2005-3389</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2005-3389.html</URL>
        <Description>CVE-2005-3389</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/118976</URL>
        <Description>SUSE Bug 118976</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/120087</URL>
        <Description>SUSE Bug 120087</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/130227</URL>
        <Description>SUSE Bug 130227</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131578</URL>
        <Description>SUSE Bug 131578</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131579</URL>
        <Description>SUSE Bug 131579</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131580</URL>
        <Description>SUSE Bug 131580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/132684</URL>
        <Description>SUSE Bug 132684</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/135480</URL>
        <Description>SUSE Bug 135480</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/307272</URL>
        <Description>SUSE Bug 307272</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field.</Note>
    </Notes>
    <CVE>CVE-2005-3390</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2005-3390.html</URL>
        <Description>CVE-2005-3390</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/118976</URL>
        <Description>SUSE Bug 118976</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/120087</URL>
        <Description>SUSE Bug 120087</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/130227</URL>
        <Description>SUSE Bug 130227</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131578</URL>
        <Description>SUSE Bug 131578</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131579</URL>
        <Description>SUSE Bug 131579</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131580</URL>
        <Description>SUSE Bug 131580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/132684</URL>
        <Description>SUSE Bug 132684</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/135480</URL>
        <Description>SUSE Bug 135480</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple vulnerabilities in PHP before 4.4.1 allow remote attackers to bypass safe_mode and open_basedir restrictions via unknown attack vectors in (1) ext/curl and (2) ext/gd.</Note>
    </Notes>
    <CVE>CVE-2005-3391</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2005-3391.html</URL>
        <Description>CVE-2005-3391</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131580</URL>
        <Description>SUSE Bug 131580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/135673</URL>
        <Description>SUSE Bug 135673</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.</Note>
    </Notes>
    <CVE>CVE-2005-3392</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2005-3392.html</URL>
        <Description>CVE-2005-3392</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/131580</URL>
        <Description>SUSE Bug 131580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/135673</URL>
        <Description>SUSE Bug 135673</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.</Note>
    </Notes>
    <CVE>CVE-2006-0996</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-0996.html</URL>
        <Description>CVE-2006-0996</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/164804</URL>
        <Description>SUSE Bug 164804</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/164845</URL>
        <Description>SUSE Bug 164845</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.</Note>
    </Notes>
    <CVE>CVE-2006-1017</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-1017.html</URL>
        <Description>CVE-2006-1017</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/154317</URL>
        <Description>SUSE Bug 154317</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/279863</URL>
        <Description>SUSE Bug 279863</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.</Note>
    </Notes>
    <CVE>CVE-2006-1490</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-1490.html</URL>
        <Description>CVE-2006-1490</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/161718</URL>
        <Description>SUSE Bug 161718</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/164845</URL>
        <Description>SUSE Bug 164845</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.</Note>
    </Notes>
    <CVE>CVE-2006-1494</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-1494.html</URL>
        <Description>CVE-2006-1494</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/164845</URL>
        <Description>SUSE Bug 164845</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.</Note>
    </Notes>
    <CVE>CVE-2006-1991</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-1991.html</URL>
        <Description>CVE-2006-1991</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/169038</URL>
        <Description>SUSE Bug 169038</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.</Note>
    </Notes>
    <CVE>CVE-2006-7243</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-7243.html</URL>
        <Description>CVE-2006-7243</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1067090</URL>
        <Description>SUSE Bug 1067090</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/654853</URL>
        <Description>SUSE Bug 654853</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/893855</URL>
        <Description>SUSE Bug 893855</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924970</URL>
        <Description>SUSE Bug 924970</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The iconv_substr function in PHP 5.2.4 and earlier allows context-dependent attackers to cause (1) a denial of service (application crash) via a long string in the charset parameter, probably also requiring a long string in the str parameter; or (2) a denial of service (temporary application hang) via a long string in the str parameter.  NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.</Note>
    </Notes>
    <CVE>CVE-2007-4783</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2007-4783.html</URL>
        <Description>CVE-2007-4783</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/308069</URL>
        <Description>SUSE Bug 308069</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/325827</URL>
        <Description>SUSE Bug 325827</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter.  NOTE: there are limited usage scenarios under which this would be a vulnerability.</Note>
    </Notes>
    <CVE>CVE-2007-4887</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2007-4887.html</URL>
        <Description>CVE-2007-4887</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/325657</URL>
        <Description>SUSE Bug 325657</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.</Note>
    </Notes>
    <CVE>CVE-2008-0599</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2008-0599.html</URL>
        <Description>CVE-2008-0599</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/387745</URL>
        <Description>SUSE Bug 387745</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/393279</URL>
        <Description>SUSE Bug 393279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.</Note>
    </Notes>
    <CVE>CVE-2010-2225</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-2225.html</URL>
        <Description>CVE-2010-2225</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/616232</URL>
        <Description>SUSE Bug 616232</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Format string vulnerability in stream.c in the phar extension in PHP 5.3.x through 5.3.3 allows context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the phar_stream_flush function, leading to errors in the php_stream_wrapper_log_error function.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2094.</Note>
    </Notes>
    <CVE>CVE-2010-2950</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-2950.html</URL>
        <Description>CVE-2010-2950</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/633934</URL>
        <Description>SUSE Bug 633934</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.</Note>
    </Notes>
    <CVE>CVE-2010-3436</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-3436.html</URL>
        <Description>CVE-2010-3436</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/642733</URL>
        <Description>SUSE Bug 642733</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.</Note>
    </Notes>
    <CVE>CVE-2010-3709</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-3709.html</URL>
        <Description>CVE-2010-3709</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/660102</URL>
        <Description>SUSE Bug 660102</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Stack consumption vulnerability in the filter_var function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL mode is used, allows remote attackers to cause a denial of service (memory consumption and application crash) via a long e-mail address string.</Note>
    </Notes>
    <CVE>CVE-2010-3710</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-3710.html</URL>
        <Description>CVE-2010-3710</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/649210</URL>
        <Description>SUSE Bug 649210</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.</Note>
    </Notes>
    <CVE>CVE-2010-4150</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-4150.html</URL>
        <Description>CVE-2010-4150</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/655968</URL>
        <Description>SUSE Bug 655968</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.</Note>
    </Notes>
    <CVE>CVE-2010-4645</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-4645.html</URL>
        <Description>CVE-2010-4645</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/662932</URL>
        <Description>SUSE Bug 662932</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependent attackers to cause a denial of service (crash) via an invalid size argument, which triggers a NULL pointer dereference.</Note>
    </Notes>
    <CVE>CVE-2011-0420</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-0420.html</URL>
        <Description>CVE-2011-0420</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/672933</URL>
        <Description>SUSE Bug 672933</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.</Note>
    </Notes>
    <CVE>CVE-2011-0421</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-0421.html</URL>
        <Description>CVE-2011-0421</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/681193</URL>
        <Description>SUSE Bug 681193</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer over-read.</Note>
    </Notes>
    <CVE>CVE-2011-0708</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-0708.html</URL>
        <Description>CVE-2011-0708</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/671710</URL>
        <Description>SUSE Bug 671710</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.</Note>
    </Notes>
    <CVE>CVE-2011-1092</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-1092.html</URL>
        <Description>CVE-2011-1092</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/677782</URL>
        <Description>SUSE Bug 677782</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple format string vulnerabilities in phar_object.c in the phar extension in PHP 5.3.5 and earlier allow context-dependent attackers to obtain sensitive information from process memory, cause a denial of service (memory corruption), or possibly execute arbitrary code via format string specifiers in an argument to a class method, leading to an incorrect zend_throw_exception_ex call.</Note>
    </Notes>
    <CVE>CVE-2011-1153</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-1153.html</URL>
        <Description>CVE-2011-1153</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/778941</URL>
        <Description>SUSE Bug 778941</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the SdnToJulian function in the Calendar extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a large integer in the first argument to the cal_from_jd function.</Note>
    </Notes>
    <CVE>CVE-2011-1466</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-1466.html</URL>
        <Description>CVE-2011-1466</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="29">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."</Note>
    </Notes>
    <CVE>CVE-2011-2202</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-2202.html</URL>
        <Description>CVE-2011-2202</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/699711</URL>
        <Description>SUSE Bug 699711</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="30">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.</Note>
    </Notes>
    <CVE>CVE-2011-3379</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-3379.html</URL>
        <Description>CVE-2011-3379</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/728350</URL>
        <Description>SUSE Bug 728350</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="31">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.</Note>
    </Notes>
    <CVE>CVE-2011-4153</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-4153.html</URL>
        <Description>CVE-2011-4153</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="32">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.</Note>
    </Notes>
    <CVE>CVE-2011-4566</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-4566.html</URL>
        <Description>CVE-2011-4566</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="33">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</Note>
    </Notes>
    <CVE>CVE-2011-4885</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2011-4885.html</URL>
        <Description>CVE-2011-4885</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="34">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.</Note>
    </Notes>
    <CVE>CVE-2012-0830</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-0830.html</URL>
        <Description>CVE-2012-0830</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/733590</URL>
        <Description>SUSE Bug 733590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/736169</URL>
        <Description>SUSE Bug 736169</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/738221</URL>
        <Description>SUSE Bug 738221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741520</URL>
        <Description>SUSE Bug 741520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/741859</URL>
        <Description>SUSE Bug 741859</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742273</URL>
        <Description>SUSE Bug 742273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742806</URL>
        <Description>SUSE Bug 742806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/743308</URL>
        <Description>SUSE Bug 743308</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/744966</URL>
        <Description>SUSE Bug 744966</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/746661</URL>
        <Description>SUSE Bug 746661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/749111</URL>
        <Description>SUSE Bug 749111</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="35">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</Note>
    </Notes>
    <CVE>CVE-2012-1823</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-1823.html</URL>
        <Description>CVE-2012-1823</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226072</URL>
        <Description>SUSE Bug 1226072</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226073</URL>
        <Description>SUSE Bug 1226073</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226074</URL>
        <Description>SUSE Bug 1226074</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/760536</URL>
        <Description>SUSE Bug 760536</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/761631</URL>
        <Description>SUSE Bug 761631</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/850694</URL>
        <Description>SUSE Bug 850694</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="36">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."</Note>
    </Notes>
    <CVE>CVE-2012-2688</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-2688.html</URL>
        <Description>CVE-2012-2688</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/772582</URL>
        <Description>SUSE Bug 772582</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="37">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.</Note>
    </Notes>
    <CVE>CVE-2012-3365</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-3365.html</URL>
        <Description>CVE-2012-3365</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/772580</URL>
        <Description>SUSE Bug 772580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/772582</URL>
        <Description>SUSE Bug 772582</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="38">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.</Note>
    </Notes>
    <CVE>CVE-2013-1635</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-1635.html</URL>
        <Description>CVE-2013-1635</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/807707</URL>
        <Description>SUSE Bug 807707</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="39">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.</Note>
    </Notes>
    <CVE>CVE-2013-1643</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-1643.html</URL>
        <Description>CVE-2013-1643</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/807707</URL>
        <Description>SUSE Bug 807707</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="40">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</Note>
    </Notes>
    <CVE>CVE-2013-4113</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4113.html</URL>
        <Description>CVE-2013-4113</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/829207</URL>
        <Description>SUSE Bug 829207</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="41">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</Note>
    </Notes>
    <CVE>CVE-2013-4248</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-4248.html</URL>
        <Description>CVE-2013-4248</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/837746</URL>
        <Description>SUSE Bug 837746</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="42">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.</Note>
    </Notes>
    <CVE>CVE-2013-6420</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-6420.html</URL>
        <Description>CVE-2013-6420</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/854880</URL>
        <Description>SUSE Bug 854880</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880238</URL>
        <Description>SUSE Bug 880238</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="43">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.</Note>
    </Notes>
    <CVE>CVE-2013-6712</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-6712.html</URL>
        <Description>CVE-2013-6712</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/853045</URL>
        <Description>SUSE Bug 853045</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="44">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via invalid imagecrop arguments that lead to use of a NULL pointer as a return value, a different vulnerability than CVE-2013-7226.</Note>
    </Notes>
    <CVE>CVE-2013-7327</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-7327.html</URL>
        <Description>CVE-2013-7327</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/864879</URL>
        <Description>SUSE Bug 864879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="45">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.</Note>
    </Notes>
    <CVE>CVE-2013-7345</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-7345.html</URL>
        <Description>CVE-2013-7345</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/869906</URL>
        <Description>SUSE Bug 869906</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883306</URL>
        <Description>SUSE Bug 883306</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/987530</URL>
        <Description>SUSE Bug 987530</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="46">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.</Note>
    </Notes>
    <CVE>CVE-2014-0185</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0185.html</URL>
        <Description>CVE-2014-0185</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/868624</URL>
        <Description>SUSE Bug 868624</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/875826</URL>
        <Description>SUSE Bug 875826</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="47">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.</Note>
    </Notes>
    <CVE>CVE-2014-0238</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0238.html</URL>
        <Description>CVE-2014-0238</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880904</URL>
        <Description>SUSE Bug 880904</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="48">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.</Note>
    </Notes>
    <CVE>CVE-2014-1943</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-1943.html</URL>
        <Description>CVE-2014-1943</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/864343</URL>
        <Description>SUSE Bug 864343</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/864589</URL>
        <Description>SUSE Bug 864589</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883306</URL>
        <Description>SUSE Bug 883306</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="49">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.</Note>
    </Notes>
    <CVE>CVE-2014-2497</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-2497.html</URL>
        <Description>CVE-2014-2497</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/868624</URL>
        <Description>SUSE Bug 868624</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="50">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.</Note>
    </Notes>
    <CVE>CVE-2014-3538</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3538.html</URL>
        <Description>CVE-2014-3538</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/935225</URL>
        <Description>SUSE Bug 935225</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/987530</URL>
        <Description>SUSE Bug 987530</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="51">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS record, related to the dns_get_record function and the dn_expand function.  NOTE: this issue exists because of an incomplete fix for CVE-2014-4049.</Note>
    </Notes>
    <CVE>CVE-2014-3597</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3597.html</URL>
        <Description>CVE-2014-3597</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/893853</URL>
        <Description>SUSE Bug 893853</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="52">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.</Note>
    </Notes>
    <CVE>CVE-2014-3622</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3622.html</URL>
        <Description>CVE-2014-3622</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/900934</URL>
        <Description>SUSE Bug 900934</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="53">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument to the xmlrpc_set_type function or (2) a crafted argument to the xmlrpc_decode function, related to an out-of-bounds read operation.</Note>
    </Notes>
    <CVE>CVE-2014-3668</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3668.html</URL>
        <Description>CVE-2014-3668</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/902368</URL>
        <Description>SUSE Bug 902368</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="54">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.</Note>
    </Notes>
    <CVE>CVE-2014-3670</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3670.html</URL>
        <Description>CVE-2014-3670</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/902357</URL>
        <Description>SUSE Bug 902357</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="55">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.</Note>
    </Notes>
    <CVE>CVE-2014-4049</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4049.html</URL>
        <Description>CVE-2014-4049</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/882992</URL>
        <Description>SUSE Bug 882992</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/893853</URL>
        <Description>SUSE Bug 893853</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="56">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.</Note>
    </Notes>
    <CVE>CVE-2014-4670</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4670.html</URL>
        <Description>CVE-2014-4670</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/886059</URL>
        <Description>SUSE Bug 886059</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="57">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applications in certain web-hosting environments.</Note>
    </Notes>
    <CVE>CVE-2014-4698</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4698.html</URL>
        <Description>CVE-2014-4698</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/886060</URL>
        <Description>SUSE Bug 886060</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="58">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.</Note>
    </Notes>
    <CVE>CVE-2014-5459</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-5459.html</URL>
        <Description>CVE-2014-5459</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/893849</URL>
        <Description>SUSE Bug 893849</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="59">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** DISPUTED ** The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption or application crash) or possibly have unspecified other impact via unknown vectors.  NOTE: this is disputed by the vendor because the standard erealloc behavior makes the free operation unreachable.</Note>
    </Notes>
    <CVE>CVE-2014-9426</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-9426.html</URL>
        <Description>CVE-2014-9426</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/911663</URL>
        <Description>SUSE Bug 911663</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="60">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid file that begins with a # character and lacks a newline character, which causes an out-of-bounds read and might (1) allow remote attackers to obtain sensitive information from php-cgi process memory by leveraging the ability to upload a .php file or (2) trigger unexpected code execution if a valid PHP script is present in memory locations adjacent to the mapping.</Note>
    </Notes>
    <CVE>CVE-2014-9427</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-9427.html</URL>
        <Description>CVE-2014-9427</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/911664</URL>
        <Description>SUSE Bug 911664</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="61">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.</Note>
    </Notes>
    <CVE>CVE-2015-0231</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0231.html</URL>
        <Description>CVE-2015-0231</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/910659</URL>
        <Description>SUSE Bug 910659</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924972</URL>
        <Description>SUSE Bug 924972</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/992991</URL>
        <Description>SUSE Bug 992991</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="62">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."</Note>
    </Notes>
    <CVE>CVE-2015-0235</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0235.html</URL>
        <Description>CVE-2015-0235</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/844309</URL>
        <Description>SUSE Bug 844309</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/913646</URL>
        <Description>SUSE Bug 913646</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/949238</URL>
        <Description>SUSE Bug 949238</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/954983</URL>
        <Description>SUSE Bug 954983</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="63">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php_date_timezone_initialize_from_hash function or (b) DateTime data handled by the php_date_initialize_from_hash function.</Note>
    </Notes>
    <CVE>CVE-2015-0273</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0273.html</URL>
        <Description>CVE-2015-0273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/917302</URL>
        <Description>SUSE Bug 917302</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/918768</URL>
        <Description>SUSE Bug 918768</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/980366</URL>
        <Description>SUSE Bug 980366</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="64">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</Note>
    </Notes>
    <CVE>CVE-2015-1351</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-1351.html</URL>
        <Description>CVE-2015-1351</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1137633</URL>
        <Description>SUSE Bug 1137633</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="65">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.</Note>
    </Notes>
    <CVE>CVE-2015-3152</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3152.html</URL>
        <Description>CVE-2015-3152</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1037590</URL>
        <Description>SUSE Bug 1037590</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1047059</URL>
        <Description>SUSE Bug 1047059</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1088681</URL>
        <Description>SUSE Bug 1088681</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/924663</URL>
        <Description>SUSE Bug 924663</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928962</URL>
        <Description>SUSE Bug 928962</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/936407</URL>
        <Description>SUSE Bug 936407</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="66">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.</Note>
    </Notes>
    <CVE>CVE-2015-3414</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3414.html</URL>
        <Description>CVE-2015-3414</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1085790</URL>
        <Description>SUSE Bug 1085790</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190372</URL>
        <Description>SUSE Bug 1190372</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1193078</URL>
        <Description>SUSE Bug 1193078</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928700</URL>
        <Description>SUSE Bug 928700</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928701</URL>
        <Description>SUSE Bug 928701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928702</URL>
        <Description>SUSE Bug 928702</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="67">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&amp;O&gt;O) in a CREATE TABLE statement.</Note>
    </Notes>
    <CVE>CVE-2015-3415</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-3415.html</URL>
        <Description>CVE-2015-3415</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190372</URL>
        <Description>SUSE Bug 1190372</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928700</URL>
        <Description>SUSE Bug 928700</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928701</URL>
        <Description>SUSE Bug 928701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/928702</URL>
        <Description>SUSE Bug 928702</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="68">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string.</Note>
    </Notes>
    <CVE>CVE-2017-9120</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-9120.html</URL>
        <Description>CVE-2017-9120</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1103661</URL>
        <Description>SUSE Bug 1103661</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="69">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This vulnerability appears to have been fixed in after commit ac16bdf2d41724b5a65255d4c28fb0ec46bc42f5.</Note>
    </Notes>
    <CVE>CVE-2018-1000222</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-1000222.html</URL>
        <Description>CVE-2018-1000222</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1105434</URL>
        <Description>SUSE Bug 1105434</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="70">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization by crafting a tar file with `phar://[path_to_malicious_phar_file]` as path. Object injection can be used to trigger destruct in the loaded PHP classes, e.g. the Archive_Tar class itself. With Archive_Tar object injection, arbitrary file deletion can occur because `@unlink($this-&gt;_temp_tarname)` is called. If another class with useful gadget is loaded, it may possible to cause remote code execution that can result in files being deleted or possibly modified. This vulnerability appears to have been fixed in 1.4.4.</Note>
    </Notes>
    <CVE>CVE-2018-1000888</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-1000888.html</URL>
        <Description>CVE-2018-1000888</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="71">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.</Note>
    </Notes>
    <CVE>CVE-2018-12882</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-12882.html</URL>
        <Description>CVE-2018-12882</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1099098</URL>
        <Description>SUSE Bug 1099098</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="72">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file.</Note>
    </Notes>
    <CVE>CVE-2018-14851</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-14851.html</URL>
        <Description>CVE-2018-14851</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1103659</URL>
        <Description>SUSE Bug 1103659</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="73">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.</Note>
    </Notes>
    <CVE>CVE-2018-17082</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-17082.html</URL>
        <Description>CVE-2018-17082</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1108753</URL>
        <Description>SUSE Bug 1108753</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="74">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.</Note>
    </Notes>
    <CVE>CVE-2018-19935</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-19935.html</URL>
        <Description>CVE-2018-19935</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1118832</URL>
        <Description>SUSE Bug 1118832</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="75">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.</Note>
    </Notes>
    <CVE>CVE-2018-20783</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-20783.html</URL>
        <Description>CVE-2018-20783</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126713</URL>
        <Description>SUSE Bug 1126713</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1127122</URL>
        <Description>SUSE Bug 1127122</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="76">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11034</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11034.html</URL>
        <Description>CVE-2019-11034</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1132838</URL>
        <Description>SUSE Bug 1132838</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="77">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11035</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11035.html</URL>
        <Description>CVE-2019-11035</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1132837</URL>
        <Description>SUSE Bug 1132837</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="78">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11036</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11036.html</URL>
        <Description>CVE-2019-11036</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1134322</URL>
        <Description>SUSE Bug 1134322</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="79">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11039</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11039.html</URL>
        <Description>CVE-2019-11039</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1138173</URL>
        <Description>SUSE Bug 1138173</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="80">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11040</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11040.html</URL>
        <Description>CVE-2019-11040</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1138172</URL>
        <Description>SUSE Bug 1138172</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="81">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11041</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11041.html</URL>
        <Description>CVE-2019-11041</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1146360</URL>
        <Description>SUSE Bug 1146360</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="82">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.</Note>
    </Notes>
    <CVE>CVE-2019-11042</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11042.html</URL>
        <Description>CVE-2019-11042</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1145095</URL>
        <Description>SUSE Bug 1145095</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="83">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.</Note>
    </Notes>
    <CVE>CVE-2019-11043</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11043.html</URL>
        <Description>CVE-2019-11043</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1154999</URL>
        <Description>SUSE Bug 1154999</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="84">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.</Note>
    </Notes>
    <CVE>CVE-2019-11046</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-11046.html</URL>
        <Description>CVE-2019-11046</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1159924</URL>
        <Description>SUSE Bug 1159924</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="85">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.</Note>
    </Notes>
    <CVE>CVE-2019-9020</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9020.html</URL>
        <Description>CVE-2019-9020</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126711</URL>
        <Description>SUSE Bug 1126711</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="86">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This is related to phar_detect_phar_fname_ext in ext/phar/phar.c.</Note>
    </Notes>
    <CVE>CVE-2019-9021</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9021.html</URL>
        <Description>CVE-2019-9021</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126713</URL>
        <Description>SUSE Bug 1126713</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="87">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries.</Note>
    </Notes>
    <CVE>CVE-2019-9022</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9022.html</URL>
        <Description>CVE-2019-9022</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126827</URL>
        <Description>SUSE Bug 1126827</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="88">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstring/oniguruma/regcomp.c, ext/mbstring/oniguruma/regexec.c, ext/mbstring/oniguruma/regparse.c, ext/mbstring/oniguruma/enc/unicode.c, and ext/mbstring/oniguruma/src/utf32_be.c when a multibyte regular expression pattern contains invalid multibyte sequences.</Note>
    </Notes>
    <CVE>CVE-2019-9023</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9023.html</URL>
        <Description>CVE-2019-9023</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126823</URL>
        <Description>SUSE Bug 1126823</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="89">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c.</Note>
    </Notes>
    <CVE>CVE-2019-9024</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9024.html</URL>
        <Description>CVE-2019-9024</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126821</URL>
        <Description>SUSE Bug 1126821</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="90">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.</Note>
    </Notes>
    <CVE>CVE-2019-9637</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9637.html</URL>
        <Description>CVE-2019-9637</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128892</URL>
        <Description>SUSE Bug 1128892</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="91">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the maker_note-&gt;offset relationship to value_len.</Note>
    </Notes>
    <CVE>CVE-2019-9638</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9638.html</URL>
        <Description>CVE-2019-9638</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128889</URL>
        <Description>SUSE Bug 1128889</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="92">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.</Note>
    </Notes>
    <CVE>CVE-2019-9640</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9640.html</URL>
        <Description>CVE-2019-9640</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128883</URL>
        <Description>SUSE Bug 1128883</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="93">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.</Note>
    </Notes>
    <CVE>CVE-2019-9641</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9641.html</URL>
        <Description>CVE-2019-9641</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128722</URL>
        <Description>SUSE Bug 1128722</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="94">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** DISPUTED ** An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: "This issue allows theoretical compromise of security, but a practical attack is usually impossible."</Note>
    </Notes>
    <CVE>CVE-2019-9675</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-9675.html</URL>
        <Description>CVE-2019-9675</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128886</URL>
        <Description>SUSE Bug 1128886</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="95">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.</Note>
    </Notes>
    <CVE>CVE-2020-7062</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-7062.html</URL>
        <Description>CVE-2020-7062</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1165280</URL>
        <Description>SUSE Bug 1165280</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="96">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.</Note>
    </Notes>
    <CVE>CVE-2020-7063</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-7063.html</URL>
        <Description>CVE-2020-7063</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1165289</URL>
        <Description>SUSE Bug 1165289</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="97">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.</Note>
    </Notes>
    <CVE>CVE-2021-21706</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:php8-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bcmath-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-bz2-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-calendar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-cli-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ctype-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-curl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dba-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-devel-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-dom-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-enchant-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-exif-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-fileinfo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ftp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gd-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gettext-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-gmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-iconv-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-intl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-ldap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mbstring-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-mysql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-odbc-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-opcache-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-openssl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pcntl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pdo-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-pgsql-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-phar-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-posix-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-readline-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-shmop-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-snmp-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-soap-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sockets-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sodium-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sqlite-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvmsg-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvsem-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-sysvshm-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tidy-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-tokenizer-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlreader-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xmlwriter-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-xsl-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zip-8.0.11-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:php8-zlib-8.0.11-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21706.html</URL>
        <Description>CVE-2021-21706</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1191314</URL>
        <Description>SUSE Bug 1191314</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
