SuSE: 2014:0873-1: important: PHP5
Summary
PHP5 has been updated to fix four security vulnerabilities:
* Heap-based buffer overflow in DNS TXT record parsing (CVE-2014-4049)
* NULL pointer dereference in GD XPM decoder (CVE-2014-2497)
* Memory corrpution in openssl_parse_x509 (CVE-2013-6420)
* Attackers can perform man-in-the-middle attacks by specially
crafting certificates (CVE-2013-4248)
Security Issues:
* CVE-2014-4049
References
#837746 #854880 #868624 #882992
Cross- CVE-2013-4248 CVE-2013-6420 CVE-2014-2497
CVE-2014-4049
Affected Products:
SUSE Linux Enterprise Server 10 SP4 LTSS
SUSE Linux Enterprise Server 10 SP3 LTSS
https://www.suse.com/security/cve/CVE-2013-4248.html
https://www.suse.com/security/cve/CVE-2013-6420.html
https://www.suse.com/security/cve/CVE-2014-2497.html
https://www.suse.com/security/cve/CVE-2014-4049.html
https://bugzilla.novell.com/837746
https://bugzilla.novell.com/854880
https://bugzilla.novell.com/868624
https://bugzilla.novell.com/882992
https://scc.suse.com:443/patches/
https://scc.suse.com:443/patches/