VYPR

rpm package

suse/php72&distro=SUSE Linux Enterprise Module for Web and Scripting 12

pkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012

Vulnerabilities (48)

  • CVE-2019-9024Feb 22, 2019
    affected < 7.2.5-1.7.1fixed 7.2.5-1.7.1

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c.

  • CVE-2019-9023Feb 22, 2019
    affected < 7.2.5-1.7.1fixed 7.2.5-1.7.1

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstr

  • CVE-2019-9022Feb 22, 2019
    affected < 7.2.5-1.7.1fixed 7.2.5-1.7.1

    An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. Thi

  • CVE-2019-9021Feb 22, 2019
    affected < 7.2.5-1.7.1fixed 7.2.5-1.7.1

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when tryi

  • CVE-2019-9020Feb 22, 2019
    affected < 7.2.5-1.7.1fixed 7.2.5-1.7.1

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in

  • CVE-2018-20783Feb 21, 2019
    affected < 7.2.5-1.7.1fixed 7.2.5-1.7.1

    In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_

  • CVE-2015-9253Feb 19, 2018
    affected < 7.2.5-1.75.1fixed 7.2.5-1.75.1

    An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system) with a non-blocking STDIN st

  • CVE-2017-8923CriMay 12, 2017
    affected < 7.2.5-1.75.1fixed 7.2.5-1.75.1

    The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leve

Page 3 of 3