SuSE: 2012:0496-1: important: PHP5
Summary
This update of php5 fixes multiple security flaws: * CVE-2011-2202: A php5 upload filename injection was fixed. * CVE-2011-4566: A integer overflow in the EXIF extension was fixed that could be used by attackers to crash the interpreter or potentially read memory * CVE-2011-3182: Multiple NULL pointer dereferences were fixed that could lead to crashes * CVE-2011-1466: An integer overflow in the PHP calendar extension was fixed that could have led to crashes. * CVE-2011-1072: A symlink vulnerability in the PEAR installer could be exploited by local attackers to inject code. * CVE-2011-4153: missing checks of return values could allow remote attackers to cause a denial of service (NULL pointer dereference) * CVE-2011-4885: denial of service via hash collisions * CVE-2012-0057: specially crafted XSLT stylesheets could allow remote attackers to create arbitrary files with arbitrary content * CVE-2012-0781: remote attacke...
Read the Full AdvisoryReferences
#699711 #709549 #713652 #728671 #733590 #735613
#736169 #738221 #741520 #741859 #742273 #742806
#743308 #744966 #746661 #749111
Cross- CVE-2011-1072 CVE-2011-1466 CVE-2011-2202
CVE-2011-3182 CVE-2011-4153 CVE-2011-4566
CVE-2011-4885 CVE-2012-0057 CVE-2012-0781
CVE-2012-0788 CVE-2012-0789 CVE-2012-0807
CVE-2012-0830 CVE-2012-0831
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Linux Enterprise Software Development Kit 11 SP1
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP1 for VMware
SUSE Linux Enterprise Server 11 SP1
https://www.suse.com/security/cve/CVE-2011-1072.html
https://www.suse.com/security/cve/CVE-2011-1466.html
https://www.suse.com/security/cve/CVE-2011-2202.html
https://www.suse.com/security/cv...
Read the Full Advisory