Mageia 2018-0390: php security update
Summary
- Int Overflow lead to Heap OverFlow in exif_thumbnail_extract of exif.c
(CVE-2018-14883)
- heap-buffer-overflow (READ of size 48) while reading exif data
(CVE-2018-14851)
- XSS due to the header Transfer-Encoding: chunked
References
- https://bugs.mageia.org/show_bug.cgi?id=23564
- https://www.php.net/archive/2018.php
- https://www.php.net/ChangeLog-5.php
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14851
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14883
Resolution
MGASA-2018-0390 - Updated php packages fix security vulnerability
SRPMS
- 6/core/php-5.6.38-1.mga6