Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in PHP
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in PHP
ID: USN-4097-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 19.04
Datum: Mi, 14. August 2019, 07:21
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11041
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11042
Applikationen: PHP

Originalnachricht


--===============0659233688488589811==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature";
boundary="gBBFr7Ir9EOA20Yy"
Content-Disposition: inline


--gBBFr7Ir9EOA20Yy
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4097-1
August 13, 2019

php7.0, php7.2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

PHP could be made to crash or execute arbitrary code if it
received specially crafted image.

Software Description:
- php7.2: HTML-embedded scripting language interpreter
- php7.0: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2019-11041, CVE-2019-11042)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
libapache2-mod-php7.2 7.2.19-0ubuntu0.19.04.2
php7.2-cgi 7.2.19-0ubuntu0.19.04.2
php7.2-cli 7.2.19-0ubuntu0.19.04.2
php7.2-fpm 7.2.19-0ubuntu0.19.04.2
php7.2-xmlrpc 7.2.19-0ubuntu0.19.04.2

Ubuntu 18.04 LTS:
libapache2-mod-php7.2 7.2.19-0ubuntu0.18.04.2
php7.2-cgi 7.2.19-0ubuntu0.18.04.2
php7.2-cli 7.2.19-0ubuntu0.18.04.2
php7.2-fpm 7.2.19-0ubuntu0.18.04.2
php7.2-xmlrpc 7.2.19-0ubuntu0.18.04.2

Ubuntu 16.04 LTS:
libapache2-mod-php7.0 7.0.33-0ubuntu0.16.04.6
php7.0-cgi 7.0.33-0ubuntu0.16.04.6
php7.0-cli 7.0.33-0ubuntu0.16.04.6
php7.0-fpm 7.0.33-0ubuntu0.16.04.6
php7.0-xmlrpc 7.0.33-0ubuntu0.16.04.6

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4097-1
CVE-2019-11041, CVE-2019-11042

Package Information:
https://launchpad.net/ubuntu/+source/php7.2/7.2.19-0ubuntu0.19.04.2
https://launchpad.net/ubuntu/+source/php7.2/7.2.19-0ubuntu0.18.04.2
https://launchpad.net/ubuntu/+source/php7.0/7.0.33-0ubuntu0.16.04.6

--gBBFr7Ir9EOA20Yy
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJdUweiAAoJEEW851uECx9pW88QAKpWQBr/h4+HP4q0BorAas4q
55QXU4zmEUewG/U0qJ/+Qlo+K4GQ5TXJW+YJgRbAGcYcbcoqYSkOYk4YIarPI4uN
HBpwmZHEx2L6SU90LiW6yzbShSFk1+efPHHHDRPrYKTV/fq/3FKoYEwT0jgvVdJ+
nvjGhRQG96vL7BET3aLZcRzhrnuKSqARxk51HmEXoUXnKfY/GuMZTvVFr+Bed6P7
FfIApa86HvSRd+SxwjLQed8BM/XJNG9EvUEOIiOjNunDnntF4X4smEotlrgziZ9t
3oqSe26GcPZy4ZN8L4Byr73+gYwZc6jyIsCSsgl9Va6BXKdeyNGhI80tc7Ph0G91
wg0AoXu0pfmEcoPysndTIAOn5KwFlsnY1KhreJvD+gpUCxPeDk9UJFkng4+WNnT7
h1gmEJYa8AeU8IMy1A6hv0zELSyD8bJ2cTQ+i+IbZG099jsH6LTECMhDtya3VkEf
5oMuQmvGTRGh3OrXfPsIOXdr+tV7SptJwuZq1nOQwcfXti+rUkKgy5HM/R1TYurO
5c3Ni9piJMWct1Ex918hyAPL1PuU+cstNG94hQjACV30Eqf508sEesZXWt6mWeJ/
qv7M64eXeCFUgyQLHlnq2dnfZsi38juBJq9sKSWMN5zBFVqHnOWiPXIq24tj7ZVH
z/YpS4gbJqZ4pr+fbm3J
=aJzL
-----END PGP SIGNATURE-----

--gBBFr7Ir9EOA20Yy--


--===============0659233688488589811==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung