Security update for php5
SUSE Patch
security@suse.de
SUSE Security Team
SUSE-SU-2017:2518-1
Final
1
1
2017-09-18T09:40:43Z
current
2017-09-18T09:40:43Z
2017-09-18T09:40:43Z
cve-database/bin/generate-cvrf.pl
2017-02-24T01:00:00Z
Security update for php5
This update for php5 fixes on issues.
This security issue was fixed:
- CVE-2017-12933: The finish_nested_data function in ext/standard/var_unserializer.re was prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue could have had an unspecified impact on the integrity of PHP (bsc#1054430)
The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
SUSE-SLE-Module-Web-Scripting-12-2017-1557,SUSE-SLE-SDK-12-SP2-2017-1557,SUSE-SLE-SDK-12-SP3-2017-1557
Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)
https://www.suse.com/support/update/announcement/2017/suse-su-20172518-1/
Link for SUSE-SU-2017:2518-1
https://lists.suse.com/pipermail/sle-security-updates/2017-September/003243.html
E-Mail link for SUSE-SU-2017:2518-1
https://www.suse.com/support/security/rating/
SUSE Security Ratings
https://bugzilla.suse.com/1054430
SUSE Bug 1054430
https://www.suse.com/security/cve/CVE-2017-12933/
SUSE CVE CVE-2017-12933 page
SUSE Linux Enterprise Module for Web and Scripting 12
SUSE Linux Enterprise Software Development Kit 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP3
apache2-mod_php5-5.5.14-109.8.2
php5-5.5.14-109.8.2
php5-bcmath-5.5.14-109.8.2
php5-bz2-5.5.14-109.8.2
php5-calendar-5.5.14-109.8.2
php5-ctype-5.5.14-109.8.2
php5-curl-5.5.14-109.8.2
php5-dba-5.5.14-109.8.2
php5-dom-5.5.14-109.8.2
php5-enchant-5.5.14-109.8.2
php5-exif-5.5.14-109.8.2
php5-fastcgi-5.5.14-109.8.2
php5-fileinfo-5.5.14-109.8.2
php5-fpm-5.5.14-109.8.2
php5-ftp-5.5.14-109.8.2
php5-gd-5.5.14-109.8.2
php5-gettext-5.5.14-109.8.2
php5-gmp-5.5.14-109.8.2
php5-iconv-5.5.14-109.8.2
php5-imap-5.5.14-109.8.2
php5-intl-5.5.14-109.8.2
php5-json-5.5.14-109.8.2
php5-ldap-5.5.14-109.8.2
php5-mbstring-5.5.14-109.8.2
php5-mcrypt-5.5.14-109.8.2
php5-mysql-5.5.14-109.8.2
php5-odbc-5.5.14-109.8.2
php5-opcache-5.5.14-109.8.2
php5-openssl-5.5.14-109.8.2
php5-pcntl-5.5.14-109.8.2
php5-pdo-5.5.14-109.8.2
php5-pear-5.5.14-109.8.2
php5-pgsql-5.5.14-109.8.2
php5-phar-5.5.14-109.8.2
php5-posix-5.5.14-109.8.2
php5-pspell-5.5.14-109.8.2
php5-shmop-5.5.14-109.8.2
php5-snmp-5.5.14-109.8.2
php5-soap-5.5.14-109.8.2
php5-sockets-5.5.14-109.8.2
php5-sqlite-5.5.14-109.8.2
php5-suhosin-5.5.14-109.8.2
php5-sysvmsg-5.5.14-109.8.2
php5-sysvsem-5.5.14-109.8.2
php5-sysvshm-5.5.14-109.8.2
php5-tokenizer-5.5.14-109.8.2
php5-wddx-5.5.14-109.8.2
php5-xmlreader-5.5.14-109.8.2
php5-xmlrpc-5.5.14-109.8.2
php5-xmlwriter-5.5.14-109.8.2
php5-xsl-5.5.14-109.8.2
php5-zip-5.5.14-109.8.2
php5-zlib-5.5.14-109.8.2
php5-devel-5.5.14-109.8.2
apache2-mod_php5-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-bcmath-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-bz2-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-calendar-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-ctype-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-curl-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-dba-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-dom-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-enchant-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-exif-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-fastcgi-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-fileinfo-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-fpm-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-ftp-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-gd-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-gettext-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-gmp-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-iconv-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-imap-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-intl-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-json-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-ldap-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-mbstring-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-mcrypt-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-mysql-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-odbc-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-opcache-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-openssl-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-pcntl-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-pdo-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-pear-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-pgsql-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-phar-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-posix-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-pspell-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-shmop-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-snmp-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-soap-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-sockets-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-sqlite-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-suhosin-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-sysvmsg-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-sysvsem-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-sysvshm-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-tokenizer-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-wddx-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-xmlreader-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-xmlrpc-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-xmlwriter-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-xsl-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-zip-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-zlib-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Module for Web and Scripting 12
php5-devel-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Software Development Kit 12 SP2
php5-devel-5.5.14-109.8.2 as a component of SUSE Linux Enterprise Software Development Kit 12 SP3
The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecified impact on the integrity of PHP.
CVE-2017-12933
SUSE Linux Enterprise Module for Web and Scripting 12:apache2-mod_php5-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-bcmath-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-bz2-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-calendar-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-ctype-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-curl-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-dba-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-dom-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-enchant-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-exif-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-fastcgi-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-fileinfo-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-fpm-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-ftp-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-gd-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-gettext-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-gmp-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-iconv-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-imap-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-intl-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-json-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-ldap-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-mbstring-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-mcrypt-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-mysql-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-odbc-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-opcache-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-openssl-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-pcntl-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-pdo-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-pear-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-pgsql-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-phar-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-posix-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-pspell-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-shmop-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-snmp-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-soap-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-sockets-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-sqlite-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-suhosin-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvmsg-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvsem-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-sysvshm-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-tokenizer-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-wddx-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlreader-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlrpc-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-xmlwriter-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-xsl-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-zip-5.5.14-109.8.2
SUSE Linux Enterprise Module for Web and Scripting 12:php5-zlib-5.5.14-109.8.2
SUSE Linux Enterprise Software Development Kit 12 SP2:php5-devel-5.5.14-109.8.2
SUSE Linux Enterprise Software Development Kit 12 SP3:php5-devel-5.5.14-109.8.2
moderate
4
AV:N/AC:H/Au:N/C:P/I:N/A:P
To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
https://www.suse.com/support/update/announcement/2017/suse-su-20172518-1/
https://www.suse.com/security/cve/CVE-2017-12933.html
CVE-2017-12933
https://bugzilla.suse.com/1054430
SUSE Bug 1054430