VARIoT IoT vulnerabilities database
| VAR-201604-0365 | CVE-2016-2780 | Huawei UTPS Vulnerable to arbitrary code execution |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Untrusted search path vulnerability in Huawei UTPS before UTPS-V200R003B015D15SP00C983 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL in an unspecified directory. Supplementary information : CWE Vulnerability type by CWE-426: Untrusted Search Path ( Unreliable search path ) Has been identified. Huawei UTPS is an application software for data card management run on PC by Huawei, China
| VAR-201710-0039 | CVE-2016-1261 | Juniper Networks Junos OS of J-Web Vulnerable to cross-site request forgery |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS). Juniper Junos is prone to cross-site request-forgery and denial-of-service vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application or cause denial-of-service conditions. Juniper Junos OS is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware systems. The operating system provides a secure programming interface and Junos SDK. The vulnerability stems from the program's improper handling of J-Web input
| VAR-201710-0040 | CVE-2016-1265 | Juniper Networks Junos Space Vulnerable to information disclosure |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected. Juniper Networks Junos Space Contains information disclosure vulnerabilities, certificate / password management vulnerabilities, and cross-site request forgery vulnerabilities.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. An unspecified cross-site scripting vulnerability
2. An unspecified insecure default Password vulnerability
3. An unspecified information disclosure vulnerability
4. Multiple unspecified command injection vulnerabilities. The solution supports automated configuration, monitoring, and troubleshooting of devices and services throughout their lifecycle
| VAR-201604-0057 | CVE-2016-1271 | Juniper Junos OS Vulnerability gained in |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.2 before 14.2R4, 15.1 before 15.1R1 or 15.1F2, and 15.1X49 before 15.1X49-D15 allow local users to gain privileges via crafted combinations of CLI commands and arguments, a different vulnerability than CVE-2015-3003, CVE-2014-3816, and CVE-2014-0615. Juniper Junos is prone to multiple local privilege escalation vulnerabilities.
Local attackers can exploit these issues to gain root privileges. Juniper Junos OS is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware systems. The operating system provides a secure programming interface and Junos SDK. A security vulnerability exists in Juniper Networks Junos OS. The following versions are affected: Juniper Networks Junos OS prior to 12.1X46-D45, 12.1X47 prior to 12.1X47-D30, 12.3 prior to 12.3R11, 12.3X48 prior to 12.3X48-D25, 13.2 prior to 13.2R8, 13.3 prior to 13.3R7 Version, version 14.1 before 14.1R6, version 14.2 before 14.2R4, version 15.1 before 15.1R1 or 15.1F2, version 15.1X49 before 15.1X49-D15
| VAR-201604-0056 | CVE-2016-1270 | Juniper Junos OS of rpd Service disruption in daemon (DoS) Vulnerabilities |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
The rpd daemon in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D40, 13.3 before 13.3R6, 14.1 before 14.1R4, and 14.2 before 14.2R2, when configured with BGP-based L2VPN or VPLS, allows remote attackers to cause a denial of service (daemon restart) via a crafted L2VPN family BGP update. Supplementary information : CWE Vulnerability type by CWE-19: Data Handling ( Data processing ) Has been identified. Juniper Junos is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to crash, denying service to legitimate users. Juniper Junos OS is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware systems. The operating system provides a secure programming interface and Junos SDK. The following versions are affected: Juniper Networks Junos OS prior to 12.1X44-D60, 12.1X46 prior to 12.1X46-D45, 12.1X47 prior to 12.1X47-D30, 12.3 prior to 12.3R9, 12.3X48 prior to 12.3X48-D20, 13.2 Version 13.2 before R7, version 13.2X51 before 13.2X51-D40, version 13.3 before 13.3R6, version 14.1 before 14.1R4, version 14.2 before 14.2R2
| VAR-201604-0055 | CVE-2016-1269 | Juniper Junos OS Service disruption in (DoS) Vulnerabilities |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R9, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R8, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4-S1, 15.1 before 15.1R2, 15.1X49 before 15.1X49-D30, and 16.1 before 16.1R1 allow remote attackers to cause a denial of service (socket consumption) via crafted TCP timestamps. Juniper Junos is prone to a denial-of-service vulnerability.
An attacker may exploit this issue to exhaust the resources, resulting in a denial-of-service condition. Juniper Junos OS is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware systems. The operating system provides a secure programming interface and Junos SDK. A security vulnerability exists in Juniper Networks Junos OS. The following versions are affected: Juniper Networks Junos OS prior to 12.1X44-D60, 12.1X46 prior to 12.1X46-D40, 12.1X47 prior to 12.1X47-D30, 12.3 prior to 12.3R11, 12.3X48 prior to 12.3X48-D20, 13.2 Version 13.2 before R9, Version 13.2X51 before 13.2X51-D39, Version 13.3 before 13.3R8, Version 14.1 before 14.1R6, Version 14.1X53 before 14.1X53-D30, Version 14.2 before 14.2R4-S1, Version 15.1 before 15.1R2, 15.1 Version 15.1X49 before X49-D30, version 16.1 before 16.1R1
| VAR-201604-0053 | CVE-2016-1267 | Juniper Junos OS of RPC Vulnerability to read arbitrary files in the function |
CVSS V2: 4.4 CVSS V3: 6.7 Severity: MEDIUM |
Race condition in the RPC functionality in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R3-S4, 15.1 before 15.1F2, or 15.1R2, 15.1X49 before 15.1X49-D20, and 16.1 before 16.1R1 allows local users to read, delete, or modify arbitrary files via unspecified vectors. Juniper Junos is prone to local privilege-escalation vulnerability.
Local attacker can exploit this issue to gain root privileges. Juniper Junos OS is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware systems. The operating system provides a secure programming interface and Junos SDK. The following versions are affected: Juniper Networks Junos OS prior to 12.1X44-D55, 12.1X46 prior to 12.1X46-D40, 12.1X47 prior to 12.1X47-D25, 12.3 prior to 12.3R11, 12.3X48 prior to 12.3X48-D20, 13.2 Version 13.2 before R8, Version 13.2X51 before 13.2X51-D39, Version 13.3 before 13.3R7, Version 14.1 before 14.1R6, Version 14.1X53 before 14.1X53-D30, Version 14.2 before 14.2R3-S4, Version 15.1 before 15.1F2 or 15.1R2 Version, 15.1X49 version before 15.1X49-D20, 16.1 version before 16.1R1
| VAR-201604-0052 | CVE-2016-1264 | Juniper Junos OS of Op Command privilege vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
Race condition in the Op command in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 12.3X50 before 12.3X50-D50, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D39, 13.2X52 before 13.2X52-D30, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4, 15.1 before 15.1F2 or 15.1R2, 15.1X49 before 15.1X49-D10 or 15.1X49-D20, and 16.1 before 16.1R1 allows remote authenticated users to gain privileges via the URL option. Juniper Junos is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks. Juniper Junos OS is a set of network operating system of Juniper Networks (Juniper Networks) dedicated to the company's hardware systems. The operating system provides a secure programming interface and Junos SDK. Attackers can exploit this vulnerability to obtain permissions by using URL options. The following versions are affected: Juniper Networks Junos OS prior to 12.1X44-D55, 12.1X46 prior to 12.1X46-D40, 12.1X47 prior to 12.1X47-D25, 12.3 prior to 12.3R11, 12.3X48 prior to 12.3X48-D20, 12.3 Version 12.3X50 before X50-D50, Version 13.2 before 13.2R8, Version 13.2X51 before 13.2X51-D39, Version 13.2X52 before 13.2X52-D30, Version 13.3 before 13.3R7, Version 14.1 before 14.1R6, Version 14.1 before 14.1X53-D30 X53 version, 14.2 version before 14.2R4, 15.1 version before 15.1F2 or 15.1R2, 15.1X49 version before 15.1X49-D10 or 15.1X49-D20, 16.1 version before 16.1R1
| VAR-201604-0122 | CVE-2016-4015 | SAP NetWeaver JAVA AS Service disruption in the existing enqueue server (DoS) Vulnerabilities |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka SAP Security Note 2258784.
An attacker can exploit this issue to cause denial-of-service conditions. ADVISORY INFORMATION
Title: SAP NetWeaver Enqueue Server – DoS vulnerability
Advisory ID: [ERPSCAN-16-019]
Risk: high
Advisory URL: https://erpscan.com/advisories/erpscan-16-019-sap-netweaver-enqueue-server-dos-vulnerability/
Date published: 12.04.2016
Vendors contacted: SAP
2. VULNERABILITY INFORMATION
Class: denial of service
Impact: denial of service
Remotely Exploitable: Yes
Locally Exploitable: No
CVE: CVE-2016-4015
CVSS Information
CVSS Base Score v3: 7.5 / 10
CVSS Base Vector:
AV : Attack Vector (Related exploit range) Network (N)
AC : Attack Complexity (Required attack complexity) Low (L)
PR : Privileges Required (Level of privileges needed to exploit) None (N)
UI : User Interaction (Required user participation) None (N)
S : Scope (Change in scope due to impact caused to components beyond
the vulnerable component) Unchanged (U)
C : Impact to Confidentiality None (N)
I : Impact to Integrity None (N)
A : Impact to Availability High (H)
3. VULNERABLE PACKAGES
SAP NetWeaver Enqueue Server 7.4
Other versions are probably affected too, but they were not checked.
5. SOLUTIONS AND WORKAROUNDS
To correct this vulnerability, install SAP Security Note 2258784
6. AUTHOR
Vahagn Vardanyan (ERPScan)
7. TECHNICAL DESCRIPTION
Enqueue Server allows an anonymous attacker to prevent legitimate
users from accessing the service, either by crashing or flooding it.
8. REPORT TIMELINE
Sent: 04.12.2015
Vendor response: 05.12.2015
Date of Public Advisory: 12.04.2016
9. REFERENCES
https://erpscan.com/advisories/erpscan-16-019-sap-netweaver-enqueue-server-dos-vulnerability/
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4015
10. ABOUT ERPScan Research
The company’s expertise is based on the research subdivision of
ERPScan, which is engaged in vulnerability research and analysis of
critical enterprise applications. It has achieved multiple
acknowledgments from the largest software vendors like SAP, Oracle,
Microsoft, IBM, VMware, HP for discovering more than 400
vulnerabilities in their solutions (200 of them just in SAP!).
ERPScan researchers are proud to have exposed new types of
vulnerabilities (TOP 10 Web Hacking Techniques 2012) and to be
nominated for the best server-side vulnerability at BlackHat 2013.
ERPScan experts have been invited to speak, present, and train at 60+
prime international security conferences in 25+ countries across the
continents. These include BlackHat, RSA, HITB, and private SAP
trainings in several Fortune 2000 companies.
ERPScan researchers lead the project EAS-SEC, which is focused on
enterprise application security research and awareness. They have
published 3 exhaustive annual award-winning surveys about SAP
security.
ERPScan experts have been interviewed by leading media resources and
featured in specialized info-sec publications worldwide. These include
Reuters, Yahoo, SC Magazine, The Register, CIO, PC World, DarkReading,
Heise, and Chinabyte, to name a few.
We have highly qualified experts in staff with experience in many
different fields of security, from web applications and
mobile/embedded to reverse engineering and ICS/SCADA systems,
accumulating their experience to conduct the best SAP security
research.
11. ABOUT ERPScan
ERPScan is the most respected and credible Business Application
Security provider. Founded in 2010, the company operates globally and
enables large Oil and Gas, Financial and Retail organizations to
secure their mission-critical processes. Named as an ‘Emerging Vendor’
in Security by CRN, listed among “TOP 100 SAP Solution providers” and
distinguished by 30+ other awards, ERPScan is the leading SAP SE
partner in discovering and resolving security vulnerabilities. ERPScan
consultants work with SAP SE in Walldorf to assist in improving the
security of their latest solutions.
ERPScan’s primary mission is to close the gap between technical and
business security, and provide solutions to evaluate and secure SAP
and Oracle ERP systems and business-critical applications from both,
cyber-attacks as well as internal fraud. Usually our clients are large
enterprises, Fortune 2000 companies and managed service providers
whose requirements are to actively monitor and manage security of vast
SAP landscapes on a global scale.
We ‘follow the sun’ and function in two hubs, located in the Palo Alto
and Amsterdam to provide threat intelligence services, agile support
and operate local offices and partner network spanning 20+ countries
around the globe.
Adress USA: 228 Hamilton Avenue, Fl. 3, Palo Alto, CA. 94301
Phone: 650.798.5255
Twitter: @erpscan
Scoop-it: Business Application Security
| VAR-201604-0068 | CVE-2016-2299 | Ecava IntegraXor Remote code execution vulnerability |
CVSS V2: 7.5 CVSS V3: 7.3 Severity: HIGH |
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Authentication is not required to exploit this vulnerability.The specific flaw exists in the handling of summary_opt report requests. The vulnerability is caused by the lack of input validation before using remotely supplied strings to construct SQL queries. By sending a specially crafted request to a vulnerable system, an unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code in the context of the process. Ecava IntegraXor is a web-based tool for creating and running HMI interfaces for SCADA systems. Ecava IntegraXor failed to perform input validation. Ecava IntegraXor is prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database
| VAR-201604-0080 | CVE-2016-2280 | Honeywell Uniformance Process History Database of RDISERVER Vulnerable to buffer overflow |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors. Honeywell Uniformance PHD is prone to a denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to cause the system to become unresponsive; resulting in a denial-of-service condition.
The following products are affected:
Uniformance PHD R310
Uniformance PHD R320
Uniformance PHD R321
| VAR-201604-0568 | CVE-2016-1376 | Cisco ASR 9000 IOS XR Denial of Service Vulnerability |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, aka Bug ID CSCuv78548. The Cisco IOSXRonASR9000 is a set of operating systems running on the 9000 Series routers from Cisco. A denial of service vulnerability exists in Cisco IOSXR on the Cisco ASR9000.
An attacker can exploit this issue to cause a denial-of-service condition, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCuv78548
| VAR-201604-0569 | CVE-2016-1377 | Cisco Unity Connection Vulnerable to cross-site scripting |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776. Cisco UnityConnection (UC) is a set of voice message platform from Cisco. The platform can use voice commands to make calls or listen to messages in a \342\200\234hands-free\342\200\235 manner.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue is being tracked by Cisco Bug ID CSCus21776
| VAR-201605-0118 | CVE-2016-4072 | PHP of Phar An arbitrary code execution vulnerability in the extension |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar/phar.c. PHP is prone to a denial-of-service vulnerability.
Successful exploits will allow attackers to cause a denial of service condition. Due to the nature of this issue, arbitrary code execution may be possible; this has not been confirmed. PHP (PHP: Hypertext Preprocessor, PHP: Hypertext Preprocessor) is an open source general-purpose computer scripting language jointly maintained by the PHP Group and the open source community. A security vulnerability exists in PHP's PHAR extension. The following versions are affected: PHP prior to 5.5.34, 5.6.x prior to 5.6.20, and 7.x prior to 7.0.5. ============================================================================
Ubuntu Security Notice USN-2984-1
May 24, 2016
php5, php7.0 vulnerabilities
============================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in PHP. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8865)
Hans Jerry Illikainen discovered that the PHP Zip extension incorrectly
handled certain malformed Zip archives. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-3078)
It was discovered that PHP incorrectly handled invalid indexes in the
SplDoublyLinkedList class. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-3132)
It was discovered that the PHP rawurlencode() function incorrectly handled
large strings. This issue only affected Ubuntu
16.04 LTS. (CVE-2016-4070)
It was discovered that the PHP php_snmp_error() function incorrectly
handled string formatting. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4071)
It was discovered that the PHP phar extension incorrectly handled certain
filenames in archives. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4072)
It was discovered that the PHP mb_strcut() function incorrectly handled
string formatting. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4073)
It was discovered that the PHP phar extension incorrectly handled certain
archive files. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 15.10. (CVE-2016-4342, CVE-2016-4343)
It was discovered that the PHP bcpowmod() function incorrectly handled
memory.
(CVE-2016-4537, CVE-2016-4538)
It was discovered that the PHP XML parser incorrectly handled certain
malformed XML data. (CVE-2016-4539)
It was discovered that certain PHP grapheme functions incorrectly handled
negative offsets. (CVE-2016-4540,
CVE-2016-4541)
It was discovered that PHP incorrectly handled certain malformed EXIF tags. (CVE-2016-4542, CVE-2016-4543,
CVE-2016-4544)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
libapache2-mod-php7.0 7.0.4-7ubuntu2.1
php7.0-cgi 7.0.4-7ubuntu2.1
php7.0-cli 7.0.4-7ubuntu2.1
php7.0-fpm 7.0.4-7ubuntu2.1
Ubuntu 15.10:
libapache2-mod-php5 5.6.11+dfsg-1ubuntu3.4
php5-cgi 5.6.11+dfsg-1ubuntu3.4
php5-cli 5.6.11+dfsg-1ubuntu3.4
php5-fpm 5.6.11+dfsg-1ubuntu3.4
Ubuntu 14.04 LTS:
libapache2-mod-php5 5.5.9+dfsg-1ubuntu4.17
php5-cgi 5.5.9+dfsg-1ubuntu4.17
php5-cli 5.5.9+dfsg-1ubuntu4.17
php5-fpm 5.5.9+dfsg-1ubuntu4.17
Ubuntu 12.04 LTS:
libapache2-mod-php5 5.3.10-1ubuntu3.23
php5-cgi 5.3.10-1ubuntu3.23
php5-cli 5.3.10-1ubuntu3.23
php5-fpm 5.3.10-1ubuntu3.23
In general, a standard system update will make all the necessary changes.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=====================================================================
Red Hat Security Advisory
Synopsis: Moderate: rh-php56 security, bug fix, and enhancement update
Advisory ID: RHSA-2016:2750-01
Product: Red Hat Software Collections
Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-2750.html
Issue date: 2016-11-15
CVE Names: CVE-2013-7456 CVE-2014-9767 CVE-2015-2325
CVE-2015-2326 CVE-2015-2327 CVE-2015-2328
CVE-2015-3210 CVE-2015-3217 CVE-2015-5073
CVE-2015-8381 CVE-2015-8383 CVE-2015-8384
CVE-2015-8385 CVE-2015-8386 CVE-2015-8388
CVE-2015-8391 CVE-2015-8392 CVE-2015-8395
CVE-2015-8835 CVE-2015-8865 CVE-2015-8866
CVE-2015-8867 CVE-2015-8873 CVE-2015-8874
CVE-2015-8876 CVE-2015-8877 CVE-2015-8879
CVE-2016-1903 CVE-2016-2554 CVE-2016-3074
CVE-2016-3141 CVE-2016-3142 CVE-2016-4070
CVE-2016-4071 CVE-2016-4072 CVE-2016-4073
CVE-2016-4342 CVE-2016-4343 CVE-2016-4473
CVE-2016-4537 CVE-2016-4538 CVE-2016-4539
CVE-2016-4540 CVE-2016-4541 CVE-2016-4542
CVE-2016-4543 CVE-2016-4544 CVE-2016-5093
CVE-2016-5094 CVE-2016-5096 CVE-2016-5114
CVE-2016-5399 CVE-2016-5766 CVE-2016-5767
CVE-2016-5768 CVE-2016-5770 CVE-2016-5771
CVE-2016-5772 CVE-2016-5773 CVE-2016-6128
CVE-2016-6207 CVE-2016-6288 CVE-2016-6289
CVE-2016-6290 CVE-2016-6291 CVE-2016-6292
CVE-2016-6294 CVE-2016-6295 CVE-2016-6296
CVE-2016-6297 CVE-2016-7124 CVE-2016-7125
CVE-2016-7126 CVE-2016-7127 CVE-2016-7128
CVE-2016-7129 CVE-2016-7130 CVE-2016-7131
CVE-2016-7132
=====================================================================
1. Summary:
An update for rh-php56, rh-php56-php, and rh-php56-php-pear is now
available for Red Hat Software Collections.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.2) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - noarch, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
3. Description:
PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. The rh-php56 packages provide a recent stable release of PHP
with PEAR 1.9.5 and enhanced language features including constant
expressions, variadic functions, arguments unpacking, and the interactive
debuger. The memcache, mongo, and XDebug extensions are also included.
The rh-php56 Software Collection has been upgraded to version 5.6.25, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#1356157, BZ#1365401)
Security Fixes in the rh-php56-php component:
* Several Moderate and Low impact security issues were found in PHP. Under
certain circumstances, these issues could cause PHP to crash, disclose
portions of its memory, execute arbitrary code, or impact PHP application
integrity. Space precludes documenting each of these issues in this
advisory. Refer to the CVE links in the References section for a
description of each of these vulnerabilities. (CVE-2013-7456,
CVE-2014-9767, CVE-2015-8835, CVE-2015-8865, CVE-2015-8866, CVE-2015-8867,
CVE-2015-8873, CVE-2015-8874, CVE-2015-8876, CVE-2015-8877, CVE-2015-8879,
CVE-2016-1903, CVE-2016-2554, CVE-2016-3074, CVE-2016-3141, CVE-2016-3142,
CVE-2016-4070, CVE-2016-4071, CVE-2016-4072, CVE-2016-4073, CVE-2016-4342,
CVE-2016-4343, CVE-2016-4473, CVE-2016-4537, CVE-2016-4538, CVE-2016-4539,
CVE-2016-4540, CVE-2016-4541, CVE-2016-4542, CVE-2016-4543, CVE-2016-4544,
CVE-2016-5093, CVE-2016-5094, CVE-2016-5096, CVE-2016-5114, CVE-2016-5399,
CVE-2016-5766, CVE-2016-5767, CVE-2016-5768, CVE-2016-5770, CVE-2016-5771,
CVE-2016-5772, CVE-2016-5773, CVE-2016-6128, CVE-2016-6207, CVE-2016-6288,
CVE-2016-6289, CVE-2016-6290, CVE-2016-6291, CVE-2016-6292, CVE-2016-6294,
CVE-2016-6295, CVE-2016-6296, CVE-2016-6297, CVE-2016-7124, CVE-2016-7125,
CVE-2016-7126, CVE-2016-7127, CVE-2016-7128, CVE-2016-7129, CVE-2016-7130,
CVE-2016-7131, CVE-2016-7132)
* Multiple flaws were found in the PCRE library included with the
rh-php56-php packages for Red Hat Enterprise Linux 6. (CVE-2015-2325, CVE-2015-2326, CVE-2015-2327, CVE-2015-2328,
CVE-2015-3210, CVE-2015-3217, CVE-2015-5073, CVE-2015-8381, CVE-2015-8383,
CVE-2015-8384, CVE-2015-8385, CVE-2015-8386, CVE-2015-8388, CVE-2015-8391,
CVE-2015-8392, CVE-2015-8395)
Red Hat would like to thank Hans Jerry Illikainen for reporting
CVE-2016-3074, CVE-2016-4473, and CVE-2016-5399.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the updated packages, the httpd daemon must be restarted
for the update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
1207198 - CVE-2015-2325 pcre: heap buffer overflow in compile_branch()
1207202 - CVE-2015-2326 pcre: heap buffer over-read in pcre_compile2() (8.37/23)
1228283 - CVE-2015-3217 pcre: stack overflow caused by mishandled group empty match (8.38/11)
1237223 - CVE-2015-5073 CVE-2015-8388 pcre: buffer overflow for forward reference within backward assertion with excess closing parenthesis (8.38/18)
1260716 - CVE-2014-9767 php: ZipArchive::extractTo allows for directory traversal when creating directories
1285399 - CVE-2015-2328 pcre: infinite recursion compiling pattern with recursive reference in a group with indefinite repeat (8.36/20)
1285408 - CVE-2015-2327 pcre: infinite recursion compiling pattern with zero-repeated groups that include recursive back reference (8.36/19)
1287614 - CVE-2015-8383 pcre: Buffer overflow caused by repeated conditional group (8.38/3)
1287623 - CVE-2015-3210 CVE-2015-8384 pcre: buffer overflow caused by recursive back reference by name within certain group (8.38/4)
1287629 - CVE-2015-8385 pcre: buffer overflow caused by named forward reference to duplicate group number (8.38/30)
1287636 - CVE-2015-8386 pcre: Buffer overflow caused by lookbehind assertion (8.38/6)
1287671 - CVE-2015-8391 pcre: inefficient posix character class syntax check (8.38/16)
1287690 - CVE-2015-8392 pcre: buffer overflow caused by patterns with duplicated named groups with (?| (8.38/27)
1287711 - CVE-2015-8381 CVE-2015-8395 pcre: Buffer overflow caused by duplicate named references (8.38/36)
1297710 - CVE-2016-5114 php: out-of-bounds write in fpm_log.c
1297717 - CVE-2016-1903 php: Out-of-bounds memory read via gdImageRotateInterpolated
1305536 - CVE-2016-4342 php: use of uninitialized pointer in PharFileInfo::getContent
1305543 - CVE-2016-2554 php: buffer overflow in handling of long link names in tar phar archives
1315312 - CVE-2016-3142 php: Out-of-bounds read in phar_parse_zipfile()
1315328 - CVE-2016-3141 php: Use after free in WDDX Deserialize when processing XML data
1321893 - CVE-2016-3074 php: Signedness vulnerability causing heap overflow in libgd
1323074 - CVE-2015-8835 php: type confusion issue in Soap Client call() method
1323103 - CVE-2016-4073 php: Negative size parameter in memcpy
1323106 - CVE-2016-4072 php: Invalid memory write in phar on filename containing \0 inside name
1323108 - CVE-2016-4071 php: Format string vulnerability in php_snmp_error()
1323114 - CVE-2016-4070 php: Integer overflow in php_raw_url_encode
1323118 - CVE-2015-8865 file: Buffer over-write in finfo_open with malformed magic file
1330418 - CVE-2015-8866 php: libxml_disable_entity_loader setting is shared between threads
1330420 - CVE-2015-8867 php: openssl_random_pseudo_bytes() is not cryptographically secure
1332454 - CVE-2016-4343 php: Uninitialized pointer in phar_make_dirstream()
1332860 - CVE-2016-4537 CVE-2016-4538 php: bcpowmod accepts negative scale causing heap buffer overflow corrupting _one_ definition
1332865 - CVE-2016-4542 CVE-2016-4543 CVE-2016-4544 php: Out-of-bounds heap memory read in exif_read_data() caused by malformed input
1332872 - CVE-2016-4540 CVE-2016-4541 php: OOB read in grapheme_stripos and grapheme_strpos when negative offset is used
1332877 - CVE-2016-4539 php: xml_parse_into_struct() can crash when XML parser is re-used
1336772 - CVE-2015-8874 gd: gdImageFillToBorder deep recursion leading to stack overflow
1336775 - CVE-2015-8873 php: Stack consumption vulnerability in Zend/zend_exceptions.c
1338896 - CVE-2015-8876 php: Zend/zend_exceptions.c does not validate certain Exception objects
1338907 - CVE-2015-8877 gd: gdImageScaleTwoPass function in gd_interpolation.c uses inconsistent allocate and free approaches
1338912 - CVE-2015-8879 php: odbc_bindcols function mishandles driver behavior for SQL_WVARCHAR columns
1339590 - CVE-2016-5093 php: improper nul termination leading to out-of-bounds read in get_icu_value_internal
1339949 - CVE-2016-5096 php: Integer underflow causing arbitrary null write in fread/gzread
1340433 - CVE-2013-7456 gd: incorrect boundary adjustment in _gdContributionsCalc
1340738 - CVE-2016-5094 php: Integer overflow in php_html_entities()
1347772 - CVE-2016-4473 php: Invalid free() instead of efree() in phar_extract_file()
1351068 - CVE-2016-5766 gd: Integer Overflow in _gd2GetHeader() resulting in heap overflow
1351069 - CVE-2016-5767 gd: Integer Overflow in gdImagePaletteToTrueColor() resulting in heap overflow
1351168 - CVE-2016-5768 php: Double free in _php_mb_regex_ereg_replace_exec
1351171 - CVE-2016-5770 php: Int/size_t confusion in SplFileObject::fread
1351173 - CVE-2016-5771 php: Use After Free Vulnerability in PHP's GC algorithm and unserialize
1351175 - CVE-2016-5772 php: Double Free Corruption in wddx_deserialize
1351179 - CVE-2016-5773 php: ZipArchive class Use After Free Vulnerability in PHP's GC algorithm and unserialize
1351603 - CVE-2016-6128 gd: Invalid color index not properly handled
1358395 - CVE-2016-5399 php: Improper error handling in bzread()
1359698 - CVE-2016-6289 php: Integer overflow leads to buffer overflow in virtual_file_ex
1359710 - CVE-2016-6290 php: Use after free in unserialize() with Unexpected Session Deserialization
1359718 - CVE-2016-6291 php: Out-of-bounds access in exif_process_IFD_in_MAKERNOTE
1359756 - CVE-2016-6292 php: Null pointer dereference in exif_process_user_comment
1359800 - CVE-2016-6207 php,gd: Integer overflow error within _gdContributionsAlloc()
1359811 - CVE-2016-6294 php: Out-of-bounds access in locale_accept_from_http
1359815 - CVE-2016-6295 php: Use after free in SNMP with GC and unserialize()
1359822 - CVE-2016-6296 php: Heap buffer overflow vulnerability in simplestring_addn in simplestring.c
1359828 - CVE-2016-6297 php: Stack-based buffer overflow vulnerability in php_stream_zip_opener
1360322 - CVE-2016-6288 php: Buffer over-read in php_url_parse_ex
1374697 - CVE-2016-7124 php: bypass __wakeup() in deserialization of an unexpected object
1374698 - CVE-2016-7125 php: Session Data Injection Vulnerability
1374699 - CVE-2016-7126 php: select_colors write out-of-bounds
1374701 - CVE-2016-7127 php: imagegammacorrect allows arbitrary write access
1374704 - CVE-2016-7128 php: Memory Leakage In exif_process_IFD_in_TIFF
1374705 - CVE-2016-7129 php: wddx_deserialize allows illegal memory access
1374707 - CVE-2016-7130 php: wddx_deserialize null dereference
1374708 - CVE-2016-7131 php: wddx_deserialize null dereference with invalid xml
1374711 - CVE-2016-7132 php: wddx_deserialize null dereference in php_wddx_pop_element
6. Package List:
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6):
Source:
rh-php56-2.3-1.el6.src.rpm
rh-php56-php-5.6.25-1.el6.src.rpm
rh-php56-php-pear-1.9.5-4.el6.src.rpm
noarch:
rh-php56-php-pear-1.9.5-4.el6.noarch.rpm
x86_64:
rh-php56-2.3-1.el6.x86_64.rpm
rh-php56-php-5.6.25-1.el6.x86_64.rpm
rh-php56-php-bcmath-5.6.25-1.el6.x86_64.rpm
rh-php56-php-cli-5.6.25-1.el6.x86_64.rpm
rh-php56-php-common-5.6.25-1.el6.x86_64.rpm
rh-php56-php-dba-5.6.25-1.el6.x86_64.rpm
rh-php56-php-dbg-5.6.25-1.el6.x86_64.rpm
rh-php56-php-debuginfo-5.6.25-1.el6.x86_64.rpm
rh-php56-php-devel-5.6.25-1.el6.x86_64.rpm
rh-php56-php-embedded-5.6.25-1.el6.x86_64.rpm
rh-php56-php-enchant-5.6.25-1.el6.x86_64.rpm
rh-php56-php-fpm-5.6.25-1.el6.x86_64.rpm
rh-php56-php-gd-5.6.25-1.el6.x86_64.rpm
rh-php56-php-gmp-5.6.25-1.el6.x86_64.rpm
rh-php56-php-imap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-intl-5.6.25-1.el6.x86_64.rpm
rh-php56-php-ldap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-mbstring-5.6.25-1.el6.x86_64.rpm
rh-php56-php-mysqlnd-5.6.25-1.el6.x86_64.rpm
rh-php56-php-odbc-5.6.25-1.el6.x86_64.rpm
rh-php56-php-opcache-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pdo-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pgsql-5.6.25-1.el6.x86_64.rpm
rh-php56-php-process-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pspell-5.6.25-1.el6.x86_64.rpm
rh-php56-php-recode-5.6.25-1.el6.x86_64.rpm
rh-php56-php-snmp-5.6.25-1.el6.x86_64.rpm
rh-php56-php-soap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-tidy-5.6.25-1.el6.x86_64.rpm
rh-php56-php-xml-5.6.25-1.el6.x86_64.rpm
rh-php56-php-xmlrpc-5.6.25-1.el6.x86_64.rpm
rh-php56-runtime-2.3-1.el6.x86_64.rpm
rh-php56-scldevel-2.3-1.el6.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7):
Source:
rh-php56-2.3-1.el6.src.rpm
rh-php56-php-5.6.25-1.el6.src.rpm
rh-php56-php-pear-1.9.5-4.el6.src.rpm
noarch:
rh-php56-php-pear-1.9.5-4.el6.noarch.rpm
x86_64:
rh-php56-2.3-1.el6.x86_64.rpm
rh-php56-php-5.6.25-1.el6.x86_64.rpm
rh-php56-php-bcmath-5.6.25-1.el6.x86_64.rpm
rh-php56-php-cli-5.6.25-1.el6.x86_64.rpm
rh-php56-php-common-5.6.25-1.el6.x86_64.rpm
rh-php56-php-dba-5.6.25-1.el6.x86_64.rpm
rh-php56-php-dbg-5.6.25-1.el6.x86_64.rpm
rh-php56-php-debuginfo-5.6.25-1.el6.x86_64.rpm
rh-php56-php-devel-5.6.25-1.el6.x86_64.rpm
rh-php56-php-embedded-5.6.25-1.el6.x86_64.rpm
rh-php56-php-enchant-5.6.25-1.el6.x86_64.rpm
rh-php56-php-fpm-5.6.25-1.el6.x86_64.rpm
rh-php56-php-gd-5.6.25-1.el6.x86_64.rpm
rh-php56-php-gmp-5.6.25-1.el6.x86_64.rpm
rh-php56-php-imap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-intl-5.6.25-1.el6.x86_64.rpm
rh-php56-php-ldap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-mbstring-5.6.25-1.el6.x86_64.rpm
rh-php56-php-mysqlnd-5.6.25-1.el6.x86_64.rpm
rh-php56-php-odbc-5.6.25-1.el6.x86_64.rpm
rh-php56-php-opcache-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pdo-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pgsql-5.6.25-1.el6.x86_64.rpm
rh-php56-php-process-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pspell-5.6.25-1.el6.x86_64.rpm
rh-php56-php-recode-5.6.25-1.el6.x86_64.rpm
rh-php56-php-snmp-5.6.25-1.el6.x86_64.rpm
rh-php56-php-soap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-tidy-5.6.25-1.el6.x86_64.rpm
rh-php56-php-xml-5.6.25-1.el6.x86_64.rpm
rh-php56-php-xmlrpc-5.6.25-1.el6.x86_64.rpm
rh-php56-runtime-2.3-1.el6.x86_64.rpm
rh-php56-scldevel-2.3-1.el6.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6):
Source:
rh-php56-2.3-1.el6.src.rpm
rh-php56-php-5.6.25-1.el6.src.rpm
rh-php56-php-pear-1.9.5-4.el6.src.rpm
noarch:
rh-php56-php-pear-1.9.5-4.el6.noarch.rpm
x86_64:
rh-php56-2.3-1.el6.x86_64.rpm
rh-php56-php-5.6.25-1.el6.x86_64.rpm
rh-php56-php-bcmath-5.6.25-1.el6.x86_64.rpm
rh-php56-php-cli-5.6.25-1.el6.x86_64.rpm
rh-php56-php-common-5.6.25-1.el6.x86_64.rpm
rh-php56-php-dba-5.6.25-1.el6.x86_64.rpm
rh-php56-php-dbg-5.6.25-1.el6.x86_64.rpm
rh-php56-php-debuginfo-5.6.25-1.el6.x86_64.rpm
rh-php56-php-devel-5.6.25-1.el6.x86_64.rpm
rh-php56-php-embedded-5.6.25-1.el6.x86_64.rpm
rh-php56-php-enchant-5.6.25-1.el6.x86_64.rpm
rh-php56-php-fpm-5.6.25-1.el6.x86_64.rpm
rh-php56-php-gd-5.6.25-1.el6.x86_64.rpm
rh-php56-php-gmp-5.6.25-1.el6.x86_64.rpm
rh-php56-php-imap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-intl-5.6.25-1.el6.x86_64.rpm
rh-php56-php-ldap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-mbstring-5.6.25-1.el6.x86_64.rpm
rh-php56-php-mysqlnd-5.6.25-1.el6.x86_64.rpm
rh-php56-php-odbc-5.6.25-1.el6.x86_64.rpm
rh-php56-php-opcache-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pdo-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pgsql-5.6.25-1.el6.x86_64.rpm
rh-php56-php-process-5.6.25-1.el6.x86_64.rpm
rh-php56-php-pspell-5.6.25-1.el6.x86_64.rpm
rh-php56-php-recode-5.6.25-1.el6.x86_64.rpm
rh-php56-php-snmp-5.6.25-1.el6.x86_64.rpm
rh-php56-php-soap-5.6.25-1.el6.x86_64.rpm
rh-php56-php-tidy-5.6.25-1.el6.x86_64.rpm
rh-php56-php-xml-5.6.25-1.el6.x86_64.rpm
rh-php56-php-xmlrpc-5.6.25-1.el6.x86_64.rpm
rh-php56-runtime-2.3-1.el6.x86_64.rpm
rh-php56-scldevel-2.3-1.el6.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source:
rh-php56-2.3-1.el7.src.rpm
rh-php56-php-5.6.25-1.el7.src.rpm
rh-php56-php-pear-1.9.5-4.el7.src.rpm
noarch:
rh-php56-php-pear-1.9.5-4.el7.noarch.rpm
x86_64:
rh-php56-2.3-1.el7.x86_64.rpm
rh-php56-php-5.6.25-1.el7.x86_64.rpm
rh-php56-php-bcmath-5.6.25-1.el7.x86_64.rpm
rh-php56-php-cli-5.6.25-1.el7.x86_64.rpm
rh-php56-php-common-5.6.25-1.el7.x86_64.rpm
rh-php56-php-dba-5.6.25-1.el7.x86_64.rpm
rh-php56-php-dbg-5.6.25-1.el7.x86_64.rpm
rh-php56-php-debuginfo-5.6.25-1.el7.x86_64.rpm
rh-php56-php-devel-5.6.25-1.el7.x86_64.rpm
rh-php56-php-embedded-5.6.25-1.el7.x86_64.rpm
rh-php56-php-enchant-5.6.25-1.el7.x86_64.rpm
rh-php56-php-fpm-5.6.25-1.el7.x86_64.rpm
rh-php56-php-gd-5.6.25-1.el7.x86_64.rpm
rh-php56-php-gmp-5.6.25-1.el7.x86_64.rpm
rh-php56-php-intl-5.6.25-1.el7.x86_64.rpm
rh-php56-php-ldap-5.6.25-1.el7.x86_64.rpm
rh-php56-php-mbstring-5.6.25-1.el7.x86_64.rpm
rh-php56-php-mysqlnd-5.6.25-1.el7.x86_64.rpm
rh-php56-php-odbc-5.6.25-1.el7.x86_64.rpm
rh-php56-php-opcache-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pdo-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pgsql-5.6.25-1.el7.x86_64.rpm
rh-php56-php-process-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pspell-5.6.25-1.el7.x86_64.rpm
rh-php56-php-recode-5.6.25-1.el7.x86_64.rpm
rh-php56-php-snmp-5.6.25-1.el7.x86_64.rpm
rh-php56-php-soap-5.6.25-1.el7.x86_64.rpm
rh-php56-php-xml-5.6.25-1.el7.x86_64.rpm
rh-php56-php-xmlrpc-5.6.25-1.el7.x86_64.rpm
rh-php56-runtime-2.3-1.el7.x86_64.rpm
rh-php56-scldevel-2.3-1.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.2):
Source:
rh-php56-2.3-1.el7.src.rpm
rh-php56-php-5.6.25-1.el7.src.rpm
rh-php56-php-pear-1.9.5-4.el7.src.rpm
noarch:
rh-php56-php-pear-1.9.5-4.el7.noarch.rpm
x86_64:
rh-php56-2.3-1.el7.x86_64.rpm
rh-php56-php-5.6.25-1.el7.x86_64.rpm
rh-php56-php-bcmath-5.6.25-1.el7.x86_64.rpm
rh-php56-php-cli-5.6.25-1.el7.x86_64.rpm
rh-php56-php-common-5.6.25-1.el7.x86_64.rpm
rh-php56-php-dba-5.6.25-1.el7.x86_64.rpm
rh-php56-php-dbg-5.6.25-1.el7.x86_64.rpm
rh-php56-php-debuginfo-5.6.25-1.el7.x86_64.rpm
rh-php56-php-devel-5.6.25-1.el7.x86_64.rpm
rh-php56-php-embedded-5.6.25-1.el7.x86_64.rpm
rh-php56-php-enchant-5.6.25-1.el7.x86_64.rpm
rh-php56-php-fpm-5.6.25-1.el7.x86_64.rpm
rh-php56-php-gd-5.6.25-1.el7.x86_64.rpm
rh-php56-php-gmp-5.6.25-1.el7.x86_64.rpm
rh-php56-php-intl-5.6.25-1.el7.x86_64.rpm
rh-php56-php-ldap-5.6.25-1.el7.x86_64.rpm
rh-php56-php-mbstring-5.6.25-1.el7.x86_64.rpm
rh-php56-php-mysqlnd-5.6.25-1.el7.x86_64.rpm
rh-php56-php-odbc-5.6.25-1.el7.x86_64.rpm
rh-php56-php-opcache-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pdo-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pgsql-5.6.25-1.el7.x86_64.rpm
rh-php56-php-process-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pspell-5.6.25-1.el7.x86_64.rpm
rh-php56-php-recode-5.6.25-1.el7.x86_64.rpm
rh-php56-php-snmp-5.6.25-1.el7.x86_64.rpm
rh-php56-php-soap-5.6.25-1.el7.x86_64.rpm
rh-php56-php-xml-5.6.25-1.el7.x86_64.rpm
rh-php56-php-xmlrpc-5.6.25-1.el7.x86_64.rpm
rh-php56-runtime-2.3-1.el7.x86_64.rpm
rh-php56-scldevel-2.3-1.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3):
Source:
rh-php56-2.3-1.el7.src.rpm
rh-php56-php-5.6.25-1.el7.src.rpm
rh-php56-php-pear-1.9.5-4.el7.src.rpm
noarch:
rh-php56-php-pear-1.9.5-4.el7.noarch.rpm
x86_64:
rh-php56-2.3-1.el7.x86_64.rpm
rh-php56-php-5.6.25-1.el7.x86_64.rpm
rh-php56-php-bcmath-5.6.25-1.el7.x86_64.rpm
rh-php56-php-cli-5.6.25-1.el7.x86_64.rpm
rh-php56-php-common-5.6.25-1.el7.x86_64.rpm
rh-php56-php-dba-5.6.25-1.el7.x86_64.rpm
rh-php56-php-dbg-5.6.25-1.el7.x86_64.rpm
rh-php56-php-debuginfo-5.6.25-1.el7.x86_64.rpm
rh-php56-php-devel-5.6.25-1.el7.x86_64.rpm
rh-php56-php-embedded-5.6.25-1.el7.x86_64.rpm
rh-php56-php-enchant-5.6.25-1.el7.x86_64.rpm
rh-php56-php-fpm-5.6.25-1.el7.x86_64.rpm
rh-php56-php-gd-5.6.25-1.el7.x86_64.rpm
rh-php56-php-gmp-5.6.25-1.el7.x86_64.rpm
rh-php56-php-intl-5.6.25-1.el7.x86_64.rpm
rh-php56-php-ldap-5.6.25-1.el7.x86_64.rpm
rh-php56-php-mbstring-5.6.25-1.el7.x86_64.rpm
rh-php56-php-mysqlnd-5.6.25-1.el7.x86_64.rpm
rh-php56-php-odbc-5.6.25-1.el7.x86_64.rpm
rh-php56-php-opcache-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pdo-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pgsql-5.6.25-1.el7.x86_64.rpm
rh-php56-php-process-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pspell-5.6.25-1.el7.x86_64.rpm
rh-php56-php-recode-5.6.25-1.el7.x86_64.rpm
rh-php56-php-snmp-5.6.25-1.el7.x86_64.rpm
rh-php56-php-soap-5.6.25-1.el7.x86_64.rpm
rh-php56-php-xml-5.6.25-1.el7.x86_64.rpm
rh-php56-php-xmlrpc-5.6.25-1.el7.x86_64.rpm
rh-php56-runtime-2.3-1.el7.x86_64.rpm
rh-php56-scldevel-2.3-1.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source:
rh-php56-2.3-1.el7.src.rpm
rh-php56-php-5.6.25-1.el7.src.rpm
rh-php56-php-pear-1.9.5-4.el7.src.rpm
noarch:
rh-php56-php-pear-1.9.5-4.el7.noarch.rpm
x86_64:
rh-php56-2.3-1.el7.x86_64.rpm
rh-php56-php-5.6.25-1.el7.x86_64.rpm
rh-php56-php-bcmath-5.6.25-1.el7.x86_64.rpm
rh-php56-php-cli-5.6.25-1.el7.x86_64.rpm
rh-php56-php-common-5.6.25-1.el7.x86_64.rpm
rh-php56-php-dba-5.6.25-1.el7.x86_64.rpm
rh-php56-php-dbg-5.6.25-1.el7.x86_64.rpm
rh-php56-php-debuginfo-5.6.25-1.el7.x86_64.rpm
rh-php56-php-devel-5.6.25-1.el7.x86_64.rpm
rh-php56-php-embedded-5.6.25-1.el7.x86_64.rpm
rh-php56-php-enchant-5.6.25-1.el7.x86_64.rpm
rh-php56-php-fpm-5.6.25-1.el7.x86_64.rpm
rh-php56-php-gd-5.6.25-1.el7.x86_64.rpm
rh-php56-php-gmp-5.6.25-1.el7.x86_64.rpm
rh-php56-php-intl-5.6.25-1.el7.x86_64.rpm
rh-php56-php-ldap-5.6.25-1.el7.x86_64.rpm
rh-php56-php-mbstring-5.6.25-1.el7.x86_64.rpm
rh-php56-php-mysqlnd-5.6.25-1.el7.x86_64.rpm
rh-php56-php-odbc-5.6.25-1.el7.x86_64.rpm
rh-php56-php-opcache-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pdo-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pgsql-5.6.25-1.el7.x86_64.rpm
rh-php56-php-process-5.6.25-1.el7.x86_64.rpm
rh-php56-php-pspell-5.6.25-1.el7.x86_64.rpm
rh-php56-php-recode-5.6.25-1.el7.x86_64.rpm
rh-php56-php-snmp-5.6.25-1.el7.x86_64.rpm
rh-php56-php-soap-5.6.25-1.el7.x86_64.rpm
rh-php56-php-xml-5.6.25-1.el7.x86_64.rpm
rh-php56-php-xmlrpc-5.6.25-1.el7.x86_64.rpm
rh-php56-runtime-2.3-1.el7.x86_64.rpm
rh-php56-scldevel-2.3-1.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2013-7456
https://access.redhat.com/security/cve/CVE-2014-9767
https://access.redhat.com/security/cve/CVE-2015-2325
https://access.redhat.com/security/cve/CVE-2015-2326
https://access.redhat.com/security/cve/CVE-2015-2327
https://access.redhat.com/security/cve/CVE-2015-2328
https://access.redhat.com/security/cve/CVE-2015-3210
https://access.redhat.com/security/cve/CVE-2015-3217
https://access.redhat.com/security/cve/CVE-2015-5073
https://access.redhat.com/security/cve/CVE-2015-8381
https://access.redhat.com/security/cve/CVE-2015-8383
https://access.redhat.com/security/cve/CVE-2015-8384
https://access.redhat.com/security/cve/CVE-2015-8385
https://access.redhat.com/security/cve/CVE-2015-8386
https://access.redhat.com/security/cve/CVE-2015-8388
https://access.redhat.com/security/cve/CVE-2015-8391
https://access.redhat.com/security/cve/CVE-2015-8392
https://access.redhat.com/security/cve/CVE-2015-8395
https://access.redhat.com/security/cve/CVE-2015-8835
https://access.redhat.com/security/cve/CVE-2015-8865
https://access.redhat.com/security/cve/CVE-2015-8866
https://access.redhat.com/security/cve/CVE-2015-8867
https://access.redhat.com/security/cve/CVE-2015-8873
https://access.redhat.com/security/cve/CVE-2015-8874
https://access.redhat.com/security/cve/CVE-2015-8876
https://access.redhat.com/security/cve/CVE-2015-8877
https://access.redhat.com/security/cve/CVE-2015-8879
https://access.redhat.com/security/cve/CVE-2016-1903
https://access.redhat.com/security/cve/CVE-2016-2554
https://access.redhat.com/security/cve/CVE-2016-3074
https://access.redhat.com/security/cve/CVE-2016-3141
https://access.redhat.com/security/cve/CVE-2016-3142
https://access.redhat.com/security/cve/CVE-2016-4070
https://access.redhat.com/security/cve/CVE-2016-4071
https://access.redhat.com/security/cve/CVE-2016-4072
https://access.redhat.com/security/cve/CVE-2016-4073
https://access.redhat.com/security/cve/CVE-2016-4342
https://access.redhat.com/security/cve/CVE-2016-4343
https://access.redhat.com/security/cve/CVE-2016-4473
https://access.redhat.com/security/cve/CVE-2016-4537
https://access.redhat.com/security/cve/CVE-2016-4538
https://access.redhat.com/security/cve/CVE-2016-4539
https://access.redhat.com/security/cve/CVE-2016-4540
https://access.redhat.com/security/cve/CVE-2016-4541
https://access.redhat.com/security/cve/CVE-2016-4542
https://access.redhat.com/security/cve/CVE-2016-4543
https://access.redhat.com/security/cve/CVE-2016-4544
https://access.redhat.com/security/cve/CVE-2016-5093
https://access.redhat.com/security/cve/CVE-2016-5094
https://access.redhat.com/security/cve/CVE-2016-5096
https://access.redhat.com/security/cve/CVE-2016-5114
https://access.redhat.com/security/cve/CVE-2016-5399
https://access.redhat.com/security/cve/CVE-2016-5766
https://access.redhat.com/security/cve/CVE-2016-5767
https://access.redhat.com/security/cve/CVE-2016-5768
https://access.redhat.com/security/cve/CVE-2016-5770
https://access.redhat.com/security/cve/CVE-2016-5771
https://access.redhat.com/security/cve/CVE-2016-5772
https://access.redhat.com/security/cve/CVE-2016-5773
https://access.redhat.com/security/cve/CVE-2016-6128
https://access.redhat.com/security/cve/CVE-2016-6207
https://access.redhat.com/security/cve/CVE-2016-6288
https://access.redhat.com/security/cve/CVE-2016-6289
https://access.redhat.com/security/cve/CVE-2016-6290
https://access.redhat.com/security/cve/CVE-2016-6291
https://access.redhat.com/security/cve/CVE-2016-6292
https://access.redhat.com/security/cve/CVE-2016-6294
https://access.redhat.com/security/cve/CVE-2016-6295
https://access.redhat.com/security/cve/CVE-2016-6296
https://access.redhat.com/security/cve/CVE-2016-6297
https://access.redhat.com/security/cve/CVE-2016-7124
https://access.redhat.com/security/cve/CVE-2016-7125
https://access.redhat.com/security/cve/CVE-2016-7126
https://access.redhat.com/security/cve/CVE-2016-7127
https://access.redhat.com/security/cve/CVE-2016-7128
https://access.redhat.com/security/cve/CVE-2016-7129
https://access.redhat.com/security/cve/CVE-2016-7130
https://access.redhat.com/security/cve/CVE-2016-7131
https://access.redhat.com/security/cve/CVE-2016-7132
https://access.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2016 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iD8DBQFYKvj4XlSAg2UNWIIRAqg2AKCB6Jcysv4gkiktKAJA3gy+RKlAqwCeJpjs
UCuj+0gWfBsWXOgFhgH0uL8=
=FcPG
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-3560-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
April 27, 2016 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : php5
CVE ID : CVE-2015-8865 CVE-2016-4070 CVE-2016-4071 CVE-2016-4072
CVE-2016-4073
Several vulnerabilities were found in PHP, a general-purpose scripting
language commonly used for web application development. Please refer to the
upstream changelog for more information:
https://php.net/ChangeLog-5.php#5.6.20
For the stable distribution (jessie), these problems have been fixed in
version 5.6.20+dfsg-0+deb8u1.
We recommend that you upgrade your php5 packages. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Note: the current version of the following document is available here:
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05240731
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c05240731
Version: 1
HPSBNS03635 rev.1 - HPE NonStop Servers OSS Script Languages running Perl and
PHP, Multiple Local and Remote Vulnerabilities
NOTICE: The information in this Security Bulletin should be acted upon as
soon as possible.
Release Date: 2016-08-19
Last Updated: 2016-08-19
Potential Security Impact: Local Denial of Service (DoS), Elevation of
Privilege, Remote Denial of Service (DoS), Execution of Arbitrary Code,
Unauthorized Disclosure of Information, Unauthorized Modification
Source: Hewlett Packard Enterprise, Product Security Response Team
VULNERABILITY SUMMARY
Multiple potential remote and local vulnerabilities impacting Perl and PHP
have been addressed by HPE NonStop Servers OSS Script Languages. The
vulnerabilities include Perl's opportunistic loading of optional modules
which might allow local users to gain elevation of privilege via a Trojan
horse library under the current working directory.
References:
- CVE-2016-1238 - Perl Local Elevation of Privilege
- CVE-2016-2381 - Perl Remote Unauthorized Modification
- CVE-2014-4330 - Perl Local Denial of Service (DoS)
**Note:** applies only for the H/J-series SPR. Fix was already
provided in a previous L-series SPR.
OSS Script Languages (T1203) T1203H01 through T1203H01^AAD, T1203L01 and
T1203L01^AAC
*Impacted releases:*
- L15.02
- L15.08.00, L15.08.01
- L16.05.00
- J06.14 through J06.16.02
- J06.17.00, J06.17.01
- J06.18.00, J06.18.01
- J06.19.00, J06.19.01, J06.19.02
- J06.20.00
- H06.25 through H06.26.01
- H06.27.00, H06.27.01
- H06.28.00, H06.28.01
- H06.29.00, H06.29.01
BACKGROUND
CVSS Base Metrics
=================
Reference, CVSS V3 Score/Vector, CVSS V2 Score/Vector
CVE-2013-7456
7.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVE-2014-4330
4.0 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
2.1 (AV:L/AC:L/Au:N/C:N/I:N/A:P)
CVE-2015-8383
7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2015-8386
7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2015-8387
7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2015-8389
7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2015-8390
7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2015-8391
8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
9.0 (AV:N/AC:L/Au:N/C:P/I:P/A:C)
CVE-2015-8393
5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVE-2015-8394
7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2015-8607
7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2015-8853
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVE-2015-8865
7.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2015-8874
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVE-2016-1238
6.7 CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
6.2 (AV:L/AC:H/Au:N/C:C/I:C/A:C)
CVE-2016-1903
9.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
6.4 (AV:N/AC:L/Au:N/C:P/I:N/A:P)
CVE-2016-2381
6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N)
CVE-2016-2554
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVE-2016-3074
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4070
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVE-2016-4071
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4072
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4073
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4342
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.3 (AV:N/AC:M/Au:N/C:P/I:P/A:C)
CVE-2016-4343
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVE-2016-4537
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4538
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4539
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4540
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4541
9.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4542
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4543
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-4544
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-5093
8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-5094
8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-5096
8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-5114
9.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
6.4 (AV:N/AC:L/Au:N/C:P/I:N/A:P)
CVE-2016-5766
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVE-2016-5767
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVE-2016-5768
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-5769
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-5770
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-5771
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-5772
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE-2016-5773
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Information on CVSS is documented in
HPE Customer Notice HPSN-2008-002 here:
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c01345499
RESOLUTION
HPE has released the following software updates to resolve the
vulnerabilities in NonStop Servers OSS Script Languages running Perl and PHP.
Install one of the SPRs below as appropriate for the system's release
version:
+ L-Series:
* T1203L01^AAE (OSS Scripting Languages) - already available
This SPR already is present in these RVUs: None
This SPR is usable with the following RVUs:
- L15.02 through L16.05.00
+ H and J-Series:
* T1203H01^AAF (OSS Scripting Languages) - already available
This SPR already is present in these RVUs: None
This SPR is usable with the following RVUs:
- J06.14 through J06.20.00
- H06.25 through H06.29.01
**Note:** Please refer to *NonStop Hotstuff HS03333* for more information.
HISTORY
Version:1 (rev.1) - 19 August 2016 Initial release
Third Party Security Patches: Third party security patches that are to be
installed on systems running Hewlett Packard Enterprise (HPE) software
products should be applied in accordance with the customer's patch management
policy.
Support: For issues about implementing the recommendations of this Security
Bulletin, contact normal HPE Services support channel. For other issues about
the content of this Security Bulletin, send e-mail to security-alert@hpe.com.
Report: To report a potential security vulnerability for any HPE supported
product:
Web form: https://www.hpe.com/info/report-security-vulnerability
Email: security-alert@hpe.com
Subscribe: To initiate a subscription to receive future HPE Security Bulletin
alerts via Email: http://www.hpe.com/support/Subscriber_Choice
Security Bulletin Archive: A list of recently released Security Bulletins is
available here: http://www.hpe.com/support/Security_Bulletin_Archive
Software Product Category: The Software Product Category is represented in
the title by the two characters following HPSB.
3C = 3COM
3P = 3rd Party Software
GN = HPE General Software
HF = HPE Hardware and Firmware
MU = Multi-Platform Software
NS = NonStop Servers
OV = OpenVMS
PV = ProCurve
ST = Storage Software
UX = HP-UX
Copyright 2016 Hewlett Packard Enterprise
Hewlett Packard Enterprise shall not be liable for technical or editorial
errors or omissions contained herein. The information provided is provided
"as is" without warranty of any kind. To the extent permitted by law, neither
HP or its affiliates, subcontractors or suppliers will be liable for
incidental,special or consequential damages including downtime cost; lost
profits; damages relating to the procurement of substitute products or
services; or damages for loss of data, or software restoration. The
information in this document is subject to change without notice. Hewlett
Packard Enterprise and the names of Hewlett Packard Enterprise products
referenced herein are trademarks of Hewlett Packard Enterprise in the United
States and other countries. Other product and company names mentioned herein
may be trademarks of their respective owners.
Background
==========
PHP is a widely-used general-purpose scripting language that is
especially suited for Web development and can be embedded into HTML.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-lang/php < 5.6.28 >= 5.6.28
Description
===========
Multiple vulnerabilities have been discovered in PHP. Please review the
CVE identifiers referenced below for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All PHP users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev=lang/php-5.6.28"
References
==========
[ 1 ] CVE-2015-8865
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8865
[ 2 ] CVE-2016-3074
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3074
[ 3 ] CVE-2016-4071
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4071
[ 4 ] CVE-2016-4072
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4072
[ 5 ] CVE-2016-4073
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4073
[ 6 ] CVE-2016-4537
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4537
[ 7 ] CVE-2016-4538
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4538
[ 8 ] CVE-2016-4539
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4539
[ 9 ] CVE-2016-4540
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4540
[ 10 ] CVE-2016-4541
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4541
[ 11 ] CVE-2016-4542
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4542
[ 12 ] CVE-2016-4543
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4543
[ 13 ] CVE-2016-4544
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4544
[ 14 ] CVE-2016-5385
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-5385
[ 15 ] CVE-2016-6289
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-6289
[ 16 ] CVE-2016-6290
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-6290
[ 17 ] CVE-2016-6291
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-6291
[ 18 ] CVE-2016-6292
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-6292
[ 19 ] CVE-2016-6294
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-6294
[ 20 ] CVE-2016-6295
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-6295
[ 21 ] CVE-2016-6296
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-6296
[ 22 ] CVE-2016-6297
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-6297
[ 23 ] CVE-2016-7124
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7124
[ 24 ] CVE-2016-7125
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7125
[ 25 ] CVE-2016-7126
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7126
[ 26 ] CVE-2016-7127
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7127
[ 27 ] CVE-2016-7128
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7128
[ 28 ] CVE-2016-7129
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7129
[ 29 ] CVE-2016-7130
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7130
[ 30 ] CVE-2016-7131
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7131
[ 31 ] CVE-2016-7132
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7132
[ 32 ] CVE-2016-7133
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7133
[ 33 ] CVE-2016-7134
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7134
[ 34 ] CVE-2016-7411
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7411
[ 35 ] CVE-2016-7412
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7412
[ 36 ] CVE-2016-7413
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7413
[ 37 ] CVE-2016-7414
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7414
[ 38 ] CVE-2016-7416
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7416
[ 39 ] CVE-2016-7417
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7417
[ 40 ] CVE-2016-7418
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7418
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/201611-22
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2016 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.5
| VAR-201604-0661 | CVE-2016-0887 | plural EMC RSA BSAFE Of the private key in the product prime Vulnerability to be acquired |
CVSS V2: 2.6 CVSS V3: 5.9 Severity: MEDIUM |
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x and 4.1.x before 4.1.5, RSA BSAFE Crypto-C Micro Edition (CCME) 4.0.x and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2.1, RSA BSAFE SSL-J before 6.2.1, and RSA BSAFE SSL-C before 2.8.9 allow remote attackers to discover a private-key prime by conducting a Lenstra side-channel attack that leverages an application's failure to detect an RSA signature failure during a TLS session. Multiple RSA BSAFE Products are prone to an information-disclosure vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks and obtain sensitive information. Successful exploits will lead to other attacks. are all products of American EMC Corporation. EMC RSA BSAFE is a security software product that supports encryption algorithms, certificate chain verification, and Transport Layer Security (TLS) cipher suites to help users achieve various security goals for their applications. EMC RSA BSAFE MES is one of the encryption toolkits. RSA BSAFE SSL-J is one of the SSL toolkits. An attacker can exploit this vulnerability to disclose the private key by establishing a TLS connection with the server.
For TLS/SSL capable toolkits an attack is carried out by attempting to establish a TLS connection to a server that implements the ServerKeyExchange message during the handshake process, negotiate Perfect Forward Secrecy and look for the ServerKeyExchange message to report a failure due to an incorrectly computed signature.
The following workaround is available for CVE-2016-0887.
It is recommended that applications verify all RSA signature creation. This includes when creating a signature with the sign APIs as well as signing certificates, CRLs, OCSP responses and CMS messages.
When using TLS in a server with an RSA certificate, the following option is available: Change the server PKI to a DSA cert and use TLS_DHE_DSS_* cipher suites.
NOTE: Servers using TLS_RSA_* cipher suites perform RSA decrypt operation and are not vulnerable but do not have Perfect Forward Secrecy.
[The following is standard text included in all security advisories. Please do not change or delete.]
Severity Rating:
For an explanation of Severity Ratings, refer to the Knowledge Base Article, \x93Security Advisories Severity Rating\x94 at https://knowledge.rsasecurity.com/scolcms/knowledge.aspx?solution=a46604. RSA recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability.
Obtaining Downloads:
To request your upgrade of the software, please call your local support telephone number (contact phone numbers are available at http://www.emc.com/support/rsa/contact/index.htm) for most expedient service.
Obtaining Documentation:
To obtain RSA documentation, log on to RSA SecurCare Online at https://knowledge.rsasecurity.com and click Products in the top navigation menu. Select the specific product whose documentation you want to obtain. Scroll to the section for the product version that you want and click the set link.
Severity Rating:
For an explanation of Severity Ratings, refer to the Knowledge Base Article, \x93Security Advisories Severity Rating\x94 at https://knowledge.rsasecurity.com/scolcms/knowledge.aspx?solution=a46604. RSA recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability.
Obtaining More Information:
For more information about RSA products, visit the RSA web site at http://www.rsa.com.
Getting Support and Service:
For customers with current maintenance contracts, contact your local RSA Customer Support center with any additional questions regarding this RSA SecurCare Note. For contact telephone numbers or e-mail addresses, log on to RSA SecurCare Online at https://knowledge.rsasecurity.com, click Help & Contact, and then click the Contact Us - Phone tab or the Contact Us - Email tab.
General Customer Support Information:
http://www.emc.com/support/rsa/index.htm
RSA SecurCare Online:
https://knowledge.rsasecurity.com
EOPS Policy:
RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the link below for additional details.
http://www.emc.com/support/rsa/eops/index.htm
SecurCare Online Security Advisories
Read and use the information in this RSA Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this product alert, contact RSA Software Technical Support at 1-800-995-5095. RSA Security LLC and its affiliates, including without limitation, its ultimate parent company, EMC Corporation, distribute RSA Security Advisories in order to bring to the attention of users of the affected RSA products, important security information. RSA recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. RSA disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall RSA, its affiliates or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if RSA, its affiliates or its suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.
About RSA SecurCare Notes & Security Advisories Subscription
RSA SecurCare Notes & Security Advisories are targeted e-mail messages that RSA sends you based on the RSA product family you currently use. If you\x92d like to stop receiving RSA SecurCare Notes & Security Advisories, or if you\x92d like to change which RSA product family Notes & Security Advisories you currently receive, log on to RSA SecurCare Online at https://knowledge.rsasecurity.com/scolcms/help.aspx?_v=view3. Following the instructions on the page, remove the check mark next to the RSA product family whose Notes & Security Advisories you no longer want to receive. Click the Submit button to save your selection.
Sincerely,
RSA Customer Support
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (Cygwin)
iEYEARECAAYFAlcL864ACgkQtjd2rKp+ALymcQCeKTDYkPRyPsXJ51agIyT9pzhs
DkoAoL5xx2e0opkTIOtucgldIM11gJh3
=GZX6
-----END PGP SIGNATURE-----
| VAR-201604-0592 | CVE-2016-2084 | plural F5 Vulnerabilities in which important information is obtained in products |
CVSS V2: 4.0 CVSS V3: 7.4 Severity: HIGH |
F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP DNS 12.0.0 before build 1.14.628; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0; BIG-IP GTM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, and 11.6.0 before build 6.204.442; BIG-IP PSM 11.3.x and 11.4.x before 11.4.1 build 685-HF10; BIG-IQ Cloud, Device, and Security 4.2.0 through 4.5.0; and BIG-IQ ADC 4.5.0 do not properly regenerate certificates and keys when deploying cloud images in Amazon Web Services (AWS), Azure or Verizon cloud services environments, which allows attackers to obtain sensitive information or cause a denial of service (disruption) by leveraging a target instance configuration. plural F5 Products, Amazon Web Services (AWS) , Azure Or Verizon When a cloud image is deployed in a cloud service environment, credentials and keys are not properly regenerated, so important information is obtained or service operation is disrupted ( Interruption ) There are vulnerabilities that are put into a state.By the attacker, Target Instance By using the settings, important information is obtained or service operation is interrupted ( Interruption ) There is a possibility of being put into a state. Multiple F5 BIG-IP products are prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause a denial-of-service condition. F5 BIG-IP LTM, etc. are all products of F5 Company in the United States. LTM is a local traffic manager; APM is a solution that provides secure unified access to business-critical applications and networks. A security vulnerability exists in several F5 BIG-IP and BIG-IQ products due to the program not properly regenerating certificates and keys. An attacker could exploit this vulnerability to disclose sensitive information
| VAR-201604-0379 | CVE-2015-8108 | plural LenovoEMC Vulnerabilities in which important device information is obtained in the product management interface |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors. plural LenovoEMC There is a vulnerability in the product's management interface that can retrieve important device information. Supplementary information : CWE Vulnerability type by CWE-254: Security Features ( Security function ) Has been identified. http://cwe.mitre.org/data/definitions/254.htmlA third party may obtain important device information. Lenovo EMC is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in further attacks. Lenovo LenovoEMC EZ Media & Backup (hm3), etc. are all firmware developed by China Lenovo (Lenovo) and used in network storage devices
| VAR-201604-0275 | CVE-2016-2393 | Lenovo Fingerprint Manager and Touch Fingerprint Vulnerability gained in |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating local checks. Multiple Lenovo Products are prone to a local privilege-escalation vulnerability.
A local attacker can exploit this vulnerability to execute arbitrary code with SYSTEM privileges. Both Lenovo Fingerprint Manager and Touch Fingerprint are products of China Lenovo (Lenovo). The former is a set of fingerprint identification sensor drivers developed for Thinkpad series; the latter is a set of driver programs for acquiring fingerprints
| VAR-201604-0669 | No CVE | Multiple security vulnerabilities exist in LG NAS N1A1 |
CVSS V2: 9.0 CVSS V3: - Severity: HIGH |
LGNASN1A1 is a network storage device developed by Korea LG Group. The Familycast service in LGNASN1A110119 has arbitrary file upload/download, secure bypass, SQL injection and unauthorized operation vulnerabilities. Attackers can use these vulnerabilities to upload or download arbitrary files, execute arbitrary script code, bypass security restrictions, access or modify. Data, exploiting potential vulnerabilities in the underlying database, gaining permissions, and performing unauthorized operations.
There are multiple security vulnerabilities in the Familycast service in LG NAS N1A1 version 10119
| VAR-201604-0307 | CVE-2016-3686 | F5 BIG-IP APM and BIG-IP Edge Gateway of Single Sign-On Important in function SessionId Information vulnerability |
CVSS V2: 4.3 CVSS V3: 5.9 Severity: MEDIUM |
The Single Sign-On (SSO) feature in F5 BIG-IP APM 11.x before 11.6.0 HF6 and BIG-IP Edge Gateway 11.0.0 through 11.3.0 might allow remote attackers to obtain sensitive SessionId information by leveraging access to the Location HTTP header in a redirect. Multiple F5 BIG-IP products are prone to an authorization-bypass vulnerability.
A remote attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. F5 BIG-IP APM (Access Policy Manager) and BIG-IP Edge Gateway are both products of the US company F5. BIG-IP APM is a solution that provides secure and unified access to business-critical applications and networks; BIG-IP Edge Gateway is a remote access solution