SuSE: 2014:0869-1: important: php53
Summary
php53 was updated to fix the following security vulnerabilities:
* Heap-based buffer overflow in DNS TXT record parsing. (CVE-2014-4049)
* Denial of service in Fileinfo component. (CVE-2014-0238)
* Performance degradation by too many file_printf calls.
(CVE-2014-0237)
* NULL pointer dereference in GD XPM decoder. (CVE-2014-2497)
Security Issues references:
* CVE-2014-4049
References
#868624 #880904 #880905 #882992
Cross- CVE-2014-0237 CVE-2014-0238 CVE-2014-2497
CVE-2014-4049
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP3
SUSE Linux Enterprise Server 11 SP3 for VMware
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP2 LTSS
https://www.suse.com/security/cve/CVE-2014-0237.html
https://www.suse.com/security/cve/CVE-2014-0238.html
https://www.suse.com/security/cve/CVE-2014-2497.html
https://www.suse.com/security/cve/CVE-2014-4049.html
https://bugzilla.novell.com/868624
https://bugzilla.novell.com/880904
https://bugzilla.novell.com/880905
https://bugzilla.novell.com/882992
https://scc.suse.com:443/patches/
https://scc.suse.com:443/patches/