ALT-BU-2019-4141-1
Branch p8 update bulletin.
Closed vulnerabilities
BDU:2020-01278
Уязвимость реализации класса PHP DirectoryIterator интерпретатора языка программирования PHP, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
BDU:2020-01291
Уязвимость функции exif_read_data интерпретатора языка программирования PHP, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
BDU:2020-01689
Уязвимость интерпретатора языка программирования PHP, связанная с чтение за границами буфера памяти, позволяющая нарушителю получить несанкционированный доступ к информации
Modified: 2024-11-21
CVE-2019-11045
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78863
- https://bugs.php.net/bug.php?id=78863
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Modified: 2024-11-21
CVE-2019-11046
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78878
- https://bugs.php.net/bug.php?id=78878
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://support.f5.com/csp/article/K48866433?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K48866433?utm_source=f5support&%3Butm_medium=RSS
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Modified: 2024-11-21
CVE-2019-11050
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78793
- https://bugs.php.net/bug.php?id=78793
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Package php7-openssl updated to version 7.2.26-alt1.1 for branch p8 in task 243177.
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Package php7-pdo_mysql updated to version 7.2.26-alt1 for branch p8 in task 243177.
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Package php7-pgsql updated to version 7.2.26-alt1.2 for branch p8 in task 243177.
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Package php7-opcache updated to version 7.2.26-alt1.1 for branch p8 in task 243177.
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Package php7-xmlrpc updated to version 7.2.26-alt1 for branch p8 in task 243177.
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14
Closed vulnerabilities
BDU:2020-01280
Уязвимость функции exif_read_data интерпретатора языка программирования PHP,связанная с чтение за границами буфера памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-11047
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
- openSUSE-SU-2020:0080
- openSUSE-SU-2020:0080
- https://bugs.php.net/bug.php?id=78910
- https://bugs.php.net/bug.php?id=78910
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- [debian-lts-announce] 20191229 [SECURITY] [DLA 2050-1] php5 security update
- FEDORA-2019-437d94e271
- FEDORA-2019-437d94e271
- FEDORA-2019-a54a622670
- FEDORA-2019-a54a622670
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200218 [SECURITY] [DSA 4626-1] php7.3 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20200219 [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update
- https://security.netapp.com/advisory/ntap-20200103-0002/
- https://security.netapp.com/advisory/ntap-20200103-0002/
- USN-4239-1
- USN-4239-1
- DSA-4626
- DSA-4626
- DSA-4628
- DSA-4628
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14