Ops One AG

You can subscribe via email or RSS

Monday 1st April 2019

Managed Server Version 5 Updates: php5-cli php5-common php5-curl php5-fpm php5-gd php5-mysql php5-readline, scheduled 4 months ago

Several vulnerabilities have been found in php5, a server-side, HTML-embedded scripting language.

  • CVE-2019-9637: rename() across the device may allow unwanted access during processing.
  • CVE-2019-9638, CVE-2019-9639: Uninitialized read in exif_process_IFD_in_MAKERNOTE.
  • CVE-2019-9640: Invalid Read on exif_process_SOFn.
  • CVE-2019-9641: Uninitialized read in exif_process_IFD_in_TIFF.
  • CVE-2019-9022: An issue during parsing of DNS responses allows a hostile DNS server to misuse memcpy, which leads to a read operation past an allocated buffer.

For Debian 8 "Jessie", these problems have been fixed in version 5.6.40+dfsg-0+deb8u2.

php5-cli/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-common/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-curl/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-fpm/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-gd/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-mysql/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]
php5-readline/oldstable 5.6.40+dfsg-0+deb8u2 amd64 [upgradable from: 5.6.40+dfsg-0+deb8u1]