Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.123689
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2013-0514)
Summary:The remote host is missing an update for the 'php' package(s) announced via the ELSA-2013-0514 advisory.
Description:Summary:
The remote host is missing an update for the 'php' package(s) announced via the ELSA-2013-0514 advisory.

Vulnerability Insight:
[5.3.3-22]
- php-xml provides php-xmlreader and php-xmlwriter (#874987)
- fix possible NULL dereference and buffer overflow (#879179)
- fix zend garbage collector (#848186, #868375)

[5.3.3-21]
- fix CVE reference in previous changelog entry

[5.3.3-20]
- remove reproducer from security fix for CVE-2012-0781

[5.3.3-19]
- add FastCGI Process Manager (php-fpm) SAPI (#806132, #824293)

[5.3.3-18]
- php script hangs when it exceeds max_execution_time
when inside an ODBC call (#864951)

[5.3.3-17]
- add security fixes for CVE-2012-2688, CVE-2012-0831, CVE-2011-1398

[5.3.3-16]
- fix stream support in fileinfo (#858653)
- fix imap_open DISABLE_AUTHENTICATOR param ignores array (#859371)

[5.3.3-15]
- fix permission on source files (#676364)
- fix negative keys with var_export (#771738)
- fix setDate when DateTime created from timestamp (#812819)
- add php(language) and missing provides (#837042)
- use arch-specific requires (#833545)
- fix possible buffer overflow in pdo_odbc (#836264)
- fix possible segfault in pdo_mysql (#824199)

Affected Software/OS:
'php' package(s) on Oracle Linux 6.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1398
https://bugs.php.net/bug.php?id=60227
http://article.gmane.org/gmane.comp.php.devel/70584
http://openwall.com/lists/oss-security/2012/08/29/5
http://openwall.com/lists/oss-security/2012/09/05/15
RedHat Security Advisories: RHSA-2013:1307
http://rhn.redhat.com/errata/RHSA-2013-1307.html
http://www.securitytracker.com/id?1027463
http://secunia.com/advisories/55078
SuSE Security Announcement: SUSE-SU-2013:1315 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00006.html
http://www.ubuntu.com/usn/USN-1569-1
Common Vulnerability Exposure (CVE) ID: CVE-2012-0831
48668
http://secunia.com/advisories/48668
51954
http://www.securityfocus.com/bid/51954
55078
APPLE-SA-2012-09-19-2
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
FEDORA-2012-6907
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080041.html
FEDORA-2012-6911
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080037.html
RHSA-2013:1307
SUSE-SU-2012:0411
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00013.html
SUSE-SU-2012:0472
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00001.html
USN-1358-1
http://www.ubuntu.com/usn/USN-1358-1
http://support.apple.com/kb/HT5501
http://svn.php.net/viewvc?view=revision&revision=323016
https://launchpadlibrarian.net/92454212/php5_5.3.2-1ubuntu4.13.diff.gz
openSUSE-SU-2012:0426
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00016.html
php-magicquotesgpc-sec-bypass(73125)
https://exchange.xforce.ibmcloud.com/vulnerabilities/73125
Common Vulnerability Exposure (CVE) ID: CVE-2012-2688
BugTraq ID: 54638
http://www.securityfocus.com/bid/54638
Debian Security Information: DSA-2527 (Google Search)
http://www.debian.org/security/2012/dsa-2527
http://www.mandriva.com/security/advisories?name=MDVSA-2012:108
http://www.securitytracker.com/id?1027287
SuSE Security Announcement: SUSE-SU-2012:1033 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00021.html
SuSE Security Announcement: SUSE-SU-2012:1034 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00022.html
SuSE Security Announcement: openSUSE-SU-2012:0976 (Google Search)
https://hermes.opensuse.org/messages/15376003
XForce ISS Database: php-phpstreamscandir-unspecified(77155)
https://exchange.xforce.ibmcloud.com/vulnerabilities/77155
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.