Nacionalni CERT

Sigurnosni nedostaci programskog paketa php

<p>--------------------------------------------------------------------------------<br />Fedora Update Notification<br />FEDORA-2017-b674dc22ad<br />2017-07-13 13:55:12.014043<br />--------------------------------------------------------------------------------<br /><br />Name : php<br />Product : Fedora 25<br />Version : 7.0.21<br />Release : 1.fc25<br />URL :<br />Summary : PHP scripting language for creating dynamic web sites<br />Description :<br />PHP is an HTML-embedded scripting language. PHP attempts to make it<br />easy for developers to write dynamically generated web pages. PHP also<br />offers built-in database integration for several commercial and<br />non-commercial database management systems, so writing a<br />database-enabled webpage with PHP is fairly simple. The most common<br />use of PHP coding is probably as a replacement for CGI scripts.<br /><br />The php package contains the module (often referred to as mod_php)<br />which adds support for the PHP language to Apache HTTP Server.<br /><br />--------------------------------------------------------------------------------<br />Update Information:<br /><br />**PHP version 7.0.21** (06 Jul 2017) **Core:** * Fixed bug php#74738 (Multiple<br />[PATH=] and [HOST=] sections not properly parsed). (Manuel Mausz) * Fixed bug<br />php#74658 (Undefined constants in array properties result in broken properties).<br />(Laruence) * Fixed misparsing of abstract unix domain socket names. (Sara) *<br />Fixed bug php#74101, bug php#74614 (Unserialize Heap Use-After-Free (READ: 1) in<br />zval_get_type). (Nikita) * Fixed bug php#74111 (Heap buffer overread (READ: 1)<br />finish_nested_data from unserialize). (Nikita) * Fixed bug php#74603 (PHP INI<br />Parsing Stack Buffer Overflow Vulnerability). (Stas) * Fixed bug php#74819<br />(wddx_deserialize() heap out-of-bound read via php_parse_date()). (Derick)<br />**DOM:** * Fixed bug php#69373 (References to deleted XPath query results).<br />(ttoohey) **Intl:** * Fixed bug php#73473 (Stack Buffer Overflow in<br />msgfmt_parse_message). (libnex) * Fixed bug php#74705 (Wrong reflection on<br />Collator::getSortKey and collator_get_sort_key). (Tyson Andre, Remi) * Fixed bug<br />php#73634 (grapheme_strpos illegal memory access). (Stas) **Mbstring:** * Add<br />oniguruma upstream fix (CVE-2017-9224, CVE-2017-9226, CVE-2017-9227,<br />CVE-2017-9228, CVE-2017-9229) (Remi, Mamoru TASAKA) **Opcache:** * Fixed bug<br />php#74663 (Segfault with opcache.memory_protect and validate_timestamp).<br />(Laruence) **OpenSSL:** * Fixed bug php#74651 (negative-size-param (-1) in<br />memcpy in zif_openssl_seal()). (Stas) **Reflection:** * Fixed bug php#74673<br />(Segfault when cast Reflection object to string with undefined constant).<br />(Laruence) **SPL:** * Fixed bug php#74478 (null coalescing operator failing<br />with SplFixedArray). (jhdxr) **Standard:** * Fixed bug php#74708 (Invalid<br />Reflection signatures for random_bytes and random_int). (Tyson Andre, Remi) *<br />Fixed bug php#73648 (Heap buffer overflow in substr). (Stas) **FTP:** * Fixed<br />bug php#74598 (ftp:// wrapper ignores context arg). (Sara) **PHAR:** * Fixed<br />bug php#74386 (Phar::__construct reflection incorrect). (villfa) **SOAP** *<br />Fixed bug php#74679 (Incorrect conversion array with WSDL_CACHE_MEMORY).<br />(Dmitry) **Streams:** * Fixed bug php#74556 (stream_socket_get_name() returns<br />'\0'). (Sara)<br />--------------------------------------------------------------------------------<br /><br />This update can be installed with the "dnf" update program. Use<br />su -c 'dnf upgrade php' at the command line.<br />For more information, refer to the dnf documentation available at<br /> /><br />All packages are signed with the Fedora Project GPG key. More details on the<br />GPG keys used by the Fedora Project can be found at<br />--------------------------------------------------------------------------------</p>
Otkriveni su sigurnosni nedostaci u programskom paketu php za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju čitanje ili pisanje podataka izvan granica dodijeljene memorije te izazivanje DoS stanja. Savjetuje se ažuriranje izdanim zakrpama.