VYPR

rpm package

suse/php7&distro=SUSE Linux Enterprise Module for Web and Scripting 15

pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015

Vulnerabilities (30)

  • CVE-2019-11050Dec 23, 2019
    affected < 7.2.5-4.49.1fixed 7.2.5-4.49.1

    When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to inf

  • CVE-2019-11047Dec 23, 2019
    affected < 7.2.5-4.49.1fixed 7.2.5-4.49.1

    When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to inf

  • CVE-2019-11046Dec 23, 2019
    affected < 7.2.5-4.49.1fixed 7.2.5-4.49.1

    In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS b

  • CVE-2019-11045Dec 23, 2019
    affected < 7.2.5-4.49.1fixed 7.2.5-4.49.1

    In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is all

  • CVE-2019-11043KEVOct 28, 2019
    affected < 7.2.5-4.46.1fixed 7.2.5-4.46.1

    In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code exec

  • CVE-2019-11042Aug 9, 2019
    affected < 7.2.5-4.40.1fixed 7.2.5-4.40.1

    When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may

  • CVE-2019-11041Aug 9, 2019
    affected < 7.2.5-4.40.1fixed 7.2.5-4.40.1

    When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may

  • CVE-2019-11040Jun 18, 2019
    affected < 7.2.5-4.35.3fixed 7.2.5-4.35.3

    When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may

  • CVE-2019-11039Jun 18, 2019
    affected < 7.2.5-4.35.3fixed 7.2.5-4.35.3

    Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.

  • CVE-2019-11036May 3, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

  • CVE-2019-11035Apr 18, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.

  • CVE-2019-11034Apr 18, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

  • CVE-2019-9675Mar 11, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot

  • CVE-2019-9641Mar 8, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.

  • CVE-2019-9640Mar 8, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.

  • CVE-2019-9639Mar 8, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.

  • CVE-2019-9638Mar 8, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the maker_note->offset relationship to value_len.

  • CVE-2019-9637Mar 8, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unau

  • CVE-2019-9024Feb 22, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c.

  • CVE-2019-9023Feb 22, 2019
    affected < 7.2.5-4.32.1fixed 7.2.5-4.32.1

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstr

Page 1 of 2

VYPR — Vulnerability Intelligence