SUSE Security Update: Security update for PHP5
______________________________________________________________________________

Announcement ID:    SUSE-SU-2012:1130-1
Rating:             important
References:         #775852 
Affected Products:
                    SUSE Linux Enterprise Server 10 SP4
                    SLE SDK 10 SP4
______________________________________________________________________________

   An update that contains security fixes can now be installed.

Description:


   This update changes the default configuration to use
   FilesMatch with  'SetHandler' rather than 'AddHandler' to
   protect weakly written web  applications from content
   confusion. Since this is a hardening measure, no  CVE was
   assigned.



Package List:

   - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64):

      apache2-mod_php5-5.2.14-0.38.1
      php5-5.2.14-0.38.1
      php5-bcmath-5.2.14-0.38.1
      php5-bz2-5.2.14-0.38.1
      php5-calendar-5.2.14-0.38.1
      php5-ctype-5.2.14-0.38.1
      php5-curl-5.2.14-0.38.1
      php5-dba-5.2.14-0.38.1
      php5-dbase-5.2.14-0.38.1
      php5-devel-5.2.14-0.38.1
      php5-dom-5.2.14-0.38.1
      php5-exif-5.2.14-0.38.1
      php5-fastcgi-5.2.14-0.38.1
      php5-ftp-5.2.14-0.38.1
      php5-gd-5.2.14-0.38.1
      php5-gettext-5.2.14-0.38.1
      php5-gmp-5.2.14-0.38.1
      php5-hash-5.2.14-0.38.1
      php5-iconv-5.2.14-0.38.1
      php5-imap-5.2.14-0.38.1
      php5-json-5.2.14-0.38.1
      php5-ldap-5.2.14-0.38.1
      php5-mbstring-5.2.14-0.38.1
      php5-mcrypt-5.2.14-0.38.1
      php5-mhash-5.2.14-0.38.1
      php5-mysql-5.2.14-0.38.1
      php5-ncurses-5.2.14-0.38.1
      php5-odbc-5.2.14-0.38.1
      php5-openssl-5.2.14-0.38.1
      php5-pcntl-5.2.14-0.38.1
      php5-pdo-5.2.14-0.38.1
      php5-pear-5.2.14-0.38.1
      php5-pgsql-5.2.14-0.38.1
      php5-posix-5.2.14-0.38.1
      php5-pspell-5.2.14-0.38.1
      php5-shmop-5.2.14-0.38.1
      php5-snmp-5.2.14-0.38.1
      php5-soap-5.2.14-0.38.1
      php5-sockets-5.2.14-0.38.1
      php5-sqlite-5.2.14-0.38.1
      php5-suhosin-5.2.14-0.38.1
      php5-sysvmsg-5.2.14-0.38.1
      php5-sysvsem-5.2.14-0.38.1
      php5-sysvshm-5.2.14-0.38.1
      php5-tokenizer-5.2.14-0.38.1
      php5-wddx-5.2.14-0.38.1
      php5-xmlreader-5.2.14-0.38.1
      php5-xmlrpc-5.2.14-0.38.1
      php5-xsl-5.2.14-0.38.1
      php5-zlib-5.2.14-0.38.1

   - SLE SDK 10 SP4 (i586 ia64 ppc s390x x86_64):

      apache2-mod_php5-5.2.14-0.38.1
      php5-5.2.14-0.38.1
      php5-bcmath-5.2.14-0.38.1
      php5-bz2-5.2.14-0.38.1
      php5-calendar-5.2.14-0.38.1
      php5-ctype-5.2.14-0.38.1
      php5-curl-5.2.14-0.38.1
      php5-dba-5.2.14-0.38.1
      php5-dbase-5.2.14-0.38.1
      php5-devel-5.2.14-0.38.1
      php5-dom-5.2.14-0.38.1
      php5-exif-5.2.14-0.38.1
      php5-fastcgi-5.2.14-0.38.1
      php5-ftp-5.2.14-0.38.1
      php5-gd-5.2.14-0.38.1
      php5-gettext-5.2.14-0.38.1
      php5-gmp-5.2.14-0.38.1
      php5-hash-5.2.14-0.38.1
      php5-iconv-5.2.14-0.38.1
      php5-imap-5.2.14-0.38.1
      php5-ldap-5.2.14-0.38.1
      php5-mbstring-5.2.14-0.38.1
      php5-mcrypt-5.2.14-0.38.1
      php5-mhash-5.2.14-0.38.1
      php5-mysql-5.2.14-0.38.1
      php5-ncurses-5.2.14-0.38.1
      php5-odbc-5.2.14-0.38.1
      php5-openssl-5.2.14-0.38.1
      php5-pcntl-5.2.14-0.38.1
      php5-pdo-5.2.14-0.38.1
      php5-pear-5.2.14-0.38.1
      php5-pgsql-5.2.14-0.38.1
      php5-posix-5.2.14-0.38.1
      php5-pspell-5.2.14-0.38.1
      php5-shmop-5.2.14-0.38.1
      php5-snmp-5.2.14-0.38.1
      php5-soap-5.2.14-0.38.1
      php5-sockets-5.2.14-0.38.1
      php5-sqlite-5.2.14-0.38.1
      php5-suhosin-5.2.14-0.38.1
      php5-sysvmsg-5.2.14-0.38.1
      php5-sysvsem-5.2.14-0.38.1
      php5-sysvshm-5.2.14-0.38.1
      php5-tidy-5.2.14-0.38.1
      php5-tokenizer-5.2.14-0.38.1
      php5-wddx-5.2.14-0.38.1
      php5-xmlreader-5.2.14-0.38.1
      php5-xmlrpc-5.2.14-0.38.1
      php5-xsl-5.2.14-0.38.1
      php5-zlib-5.2.14-0.38.1


References:

   https://bugzilla.novell.com/775852
   https://login.microfocus.com/nidp/app/login

SuSE: 2012:1130-1: important: PHP5

September 6, 2012
An update that contains security fixes can now be installed

Summary

This update changes the default configuration to use FilesMatch with 'SetHandler' rather than 'AddHandler' to protect weakly written web applications from content confusion. Since this is a hardening measure, no CVE was assigned. Package List: - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64): apache2-mod_php5-5.2.14-0.38.1 php5-5.2.14-0.38.1 php5-bcmath-5.2.14-0.38.1 php5-bz2-5.2.14-0.38.1 php5-calendar-5.2.14-0.38.1 php5-ctype-5.2.14-0.38.1 php5-curl-5.2.14-0.38.1 php5-dba-5.2.14-0.38.1 php5-dbase-5.2.14-0.38.1 php5-devel-5.2.14-0.38.1 php5-dom-5.2.14-0.38.1 php5-exif-5.2.14-0.38.1 php5-fastcgi-5.2.14-0.38.1 php5-ftp-5.2.14-0.38.1 php5-gd-5.2.14-0.38.1 php5-gettext-5.2.14-0.38.1 php5-gmp-5.2.14-0.38.1 php5-hash-5.2.14-0.38.1 php5-iconv-5.2.14-0.38.1 php5-imap-5.2.14-0.38.1 php5-json-5.2.14-0.38.1 php5-ldap-5.2.14-0.38.1 php5-mbstring-5.2.14-0.38.1 php5-mcrypt-5.2.14-0.38.1 php5-mhash-5.2.14-0.38.1 php5-mysql-5.2.14-0.38.1 php5-ncurses-5.2.14-0.38.1 php5-odbc-5.2.14-0.38.1 php5-openssl-5.2.14-0.38.1 php5-pcntl-5.2.14-0.38.1 php5-pdo-5.2.14-0.38.1 php5-pear-5.2.14-0.38.1 php5-pgsql-5.2.14-0.38.1 php5-posix-5.2.14-0.38.1 php5-pspell-5.2.14-0.38.1 php5-shmop-5.2.14-0.38.1 php5-snmp-5.2.14-0.38.1 php5-soap-5.2.14-0.38.1 php5-sockets-5.2.14-0.38.1 php5-sqlite-5.2.14-0.38.1 php5-suhosin-5.2.14-0.38.1 php5-sysvmsg-5.2.14-0.38.1 php5-sysvsem-5.2.14-0.38.1 php5-sysvshm-5.2.14-0.38.1 php5-tokenizer-5.2.14-0.38.1 php5-wddx-5.2.14-0.38.1 php5-xmlreader-5.2.14-0.38.1 php5-xmlrpc-5.2.14-0.38.1 php5-xsl-5.2.14-0.38.1 php5-zlib-5.2.14-0.38.1 - SLE SDK 10 SP4 (i586 ia64 ppc s390x x86_64): apache2-mod_php5-5.2.14-0.38.1 php5-5.2.14-0.38.1 php5-bcmath-5.2.14-0.38.1 php5-bz2-5.2.14-0.38.1 php5-calendar-5.2.14-0.38.1 php5-ctype-5.2.14-0.38.1 php5-curl-5.2.14-0.38.1 php5-dba-5.2.14-0.38.1 php5-dbase-5.2.14-0.38.1 php5-devel-5.2.14-0.38.1 php5-dom-5.2.14-0.38.1 php5-exif-5.2.14-0.38.1 php5-fastcgi-5.2.14-0.38.1 php5-ftp-5.2.14-0.38.1 php5-gd-5.2.14-0.38.1 php5-gettext-5.2.14-0.38.1 php5-gmp-5.2.14-0.38.1 php5-hash-5.2.14-0.38.1 php5-iconv-5.2.14-0.38.1 php5-imap-5.2.14-0.38.1 php5-ldap-5.2.14-0.38.1 php5-mbstring-5.2.14-0.38.1 php5-mcrypt-5.2.14-0.38.1 php5-mhash-5.2.14-0.38.1 php5-mysql-5.2.14-0.38.1 php5-ncurses-5.2.14-0.38.1 php5-odbc-5.2.14-0.38.1 php5-openssl-5.2.14-0.38.1 php5-pcntl-5.2.14-0.38.1 php5-pdo-5.2.14-0.38.1 php5-pear-5.2.14-0.38.1 php5-pgsql-5.2.14-0.38.1 php5-posix-5.2.14-0.38.1 php5-pspell-5.2.14-0.38.1 php5-shmop-5.2.14-0.38.1 php5-snmp-5.2.14-0.38.1 php5-soap-5.2.14-0.38.1 php5-sockets-5.2.14-0.38.1 php5-sqlite-5.2.14-0.38.1 php5-suhosin-5.2.14-0.38.1 php5-sysvmsg-5.2.14-0.38.1 php5-sysvsem-5.2.14-0.38.1 php5-sysvshm-5.2.14-0.38.1 php5-tidy-5.2.14-0.38.1 php5-tokenizer-5.2.14-0.38.1 php5-wddx-5.2.14-0.38.1 php5-xmlreader-5.2.14-0.38.1 php5-xmlrpc-5.2.14-0.38.1 php5-xsl-5.2.14-0.38.1 php5-zlib-5.2.14-0.38.1

References

#775852

Affected Products:

SUSE Linux Enterprise Server 10 SP4

SLE SDK 10 SP4

https://bugzilla.novell.com/775852

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2012:1130-1
Rating: important

Related News