SuSE: 2012:0598-2: critical: PHP5
Summary
This update fixes several security issues in PHP5:
* CVE-2012-1172: A directory traversal bug has been
fixed in PHP5.
* CVE-2012-1823, CVE-2012-2311: A command injection was
possible when PHP5 was operated in CGI mode using
commandline options. This problem does not affect PHP5 in
the normal apache module mode setup.
* Also a pack/unpacking bug on big endian 64bit
architectures (ppc64 and s390x) has been fixed. bnc#753778
Security Issue references:
* CVE-2012-1172
References
#752030 #753778 #760536
Cross- CVE-2012-1172 CVE-2012-1823 CVE-2012-2311
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Linux Enterprise Software Development Kit 11 SP1
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP1 for VMware
SUSE Linux Enterprise Server 11 SP1
https://www.suse.com/security/cve/CVE-2012-1172.html
https://www.suse.com/security/cve/CVE-2012-1823.html
https://www.suse.com/security/cve/CVE-2012-2311.html
https://bugzilla.novell.com/752030
https://bugzilla.novell.com/753778
https://bugzilla.novell.com/760536
https://login.microfocus.com/nidp/app/login