Several vulnerabilities have been found in php5, a server-side, HTML-embedded scripting language.
- CVE-2019-9637: rename() across the device may allow unwanted access during processing.
- CVE-2019-9638, CVE-2019-9639: Uninitialized read in exif_process_IFD_in_MAKERNOTE.
- CVE-2019-9640: Invalid Read on exif_process_SOFn.
- CVE-2019-9641: Uninitialized read in exif_process_IFD_in_TIFF.
- CVE-2019-9022: An issue during parsing of DNS responses allows a hostile DNS server to misuse memcpy, which leads to a read operation past an allocated buffer.
For Debian 8 "Jessie", these problems have been fixed in version
5.6.40+dfsg-0+deb8u2.
php5-cli/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-common/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-curl/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-fpm/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-gd/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-mysql/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-readline/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]