Lesezeichen hinzufügen
Originalnachricht
-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA512- -------------------------------------------------------------------------Debian Security Advisory DSA-4081-1 security@debian.orghttps://www.debian.org/security/ Moritz MuehlenhoffJanuary 08, 2018 https://www.debian.org/security/faq- -------------------------------------------------------------------------Package : php5CVE ID : CVE-2017-11142 CVE-2017-11143 CVE-2017-11144 CVE-2017-11145 CVE-2017-11628 CVE-2017-12933 CVE-2017-16642Several vulnerabilities were found in PHP, a widely-used open sourcegeneral purpose scripting language:CVE-2017-11142 Denial of service via overly long form variablesCVE-2017-11143 Invalid free() in wddx_deserialize()CVE-2017-11144 Denial of service in openssl extension due to incorrect return value check of OpenSSL sealing function.CVE-2017-11145 Out-of-bounds read in wddx_deserialize()CVE-2017-11628 Buffer overflow in PHP INI parsing APICVE-2017-12933 Buffer overread in finish_nested_data()CVE-2017-16642 Out-of-bounds read in timelib_meridian()For the oldstable distribution (jessie), these problems have been fixedin version 5.6.33+dfsg-0+deb8u1.We recommend that you upgrade your php5 packages.For the detailed security status of php5 please refer toits security tracker page at:https://security-tracker.debian.org/tracker/php5Further information about Debian Security Advisories, how to applythese updates to your system and frequently asked questions can befound at: https://www.debian.org/security/Mailing list: debian-security-announce@lists.debian.org-----BEGIN PGP SIGNATURE-----iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlpT7h0ACgkQEMKTtsN8TjZXmg//ckIev7tKnujmMNnfFQDzK4Tjrxe2gdJUrBa5NUvWO2kMdnyt1TiYgXpLP0VFzOax1tdRkpK7jPZ3BSziZ6Fvz1fcQm0AqxAyykN9mDRqn23unSmfkP1qL1NXZ1CJ2kjbRueUMYhgOk2rtLh4ylYMyarINHHxHCzoHYRAPjBUcAD1obauQQc+sdw+ipDZc7qUI3nY82wxTFmYiBhy7fq7YuXddEK1F2Nu0ziVR7ehnmod1l/xwpBx70HNR1ckbEzgp9ezew4q30q3s7XLpGlOQaprR/5292agXwLTkTZjmIssKAA61VLb+Yx/ogrwq1EqLVHxz05o7zj63beo+YMXeRURmwjGVpqgAqH7ozIGJvuKpGoDTRfOZ/RXLhwy2gUboc0eju1MXOqv0xMDa75m/4F3gvjj356dcNNDbfmyy/dizuO7XdcMdFDRtRX7l8eFsazYVUw2kSUQx/kEg2DnkIVre+hGKef1OL9ABygFsk2qUplFM/He7WfmMPmNlt86H1iNCKdVJOtCYDpkwZvAf/oaV8YIgCkWGyoS7T4qcnqc0W8mm7twJqPMSix9k19Gk/sOrG/QLAsNd/YI+XxdL9BjfKU5XXPrA2sIo7mypE+aedkjM78ZR1Bjx4rl6s+C2LwBczw/EN62gTjiltBRykc2aOHNCnbHhA75pojm4jQ==rHKK-----END PGP SIGNATURE-----