VYPR

rpm package

suse/php7&distro=SUSE Linux Enterprise Software Development Kit 12 SP2

pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2

Vulnerabilities (42)

  • CVE-2016-6294CriJul 25, 2016
    affected < 7.0.7-49.1fixed 7.0.7-49.1

    The locale_accept_from_http function in ext/intl/locale/locale_methods.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly restrict calls to the ICU uloc_acceptLanguageFromHTTP function, which allows remote attackers to cause a denial of service (o

  • CVE-2016-5385HigJul 19, 2016
    affected < 7.0.7-25.1fixed 7.0.7-25.1

    PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's

Page 3 of 3