MGASA-2014-0284

Source
https://advisories.mageia.org/MGASA-2014-0284.html
Import Source
https://advisories.mageia.org/MGASA-2014-0284.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0284
Related
Published
2014-07-08T22:30:04Z
Modified
2014-07-08T22:29:58Z
Summary
Updated php packages fix multiple vulnerabilities
Details

Updated php packages fix security vulnerabilities:

The unserialize() function in PHP before 5.4.30 and 5.5.14 has a Type Confusion issue related to the SPL ArrayObject and SPLObjectStorage Types (CVE-2014-3515).

It was discovered that PHP is vulnerable to a heap-based buffer overflow in the DNS TXT record parsing. A malicious server or man-in-the-middle attacker could possibly use this flaw to execute arbitrary code as the PHP interpreter if a PHP application uses dnsgetrecord() to perform a DNS query (CVE-2014-4049).

A flaw was found in the way file parsed property information from Composite Document Files (CDF) files, where the mconvert() function did not correctly compute the truncated pascal string size (CVE-2014-3478).

Multiple flaws were found in the way file parsed property information from Composite Document Files (CDF) files, due to insufficient boundary checks on buffers (CVE-2014-0207, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487).

PHP contains a bundled copy of the file utility's libmagic library, so it was vulnerable to this issue. It has been updated to versions 5.4.30 and 5.5.14, which fix this issue and several other bugs.

The phpinfo() function in PHP before 5.4.30 and 5.5.14 has a Type Confusion issue that can cause it to leak arbitrary process memory (CVE-2014-4721).

Additionally, php-apc has been rebuilt against the updated php packages.

References
Credits

Affected packages

Mageia:4 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.5.14-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / php-apc

Package

Name
php-apc
Purl
pkg:rpm/mageia/php-apc?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.15-4.5.mga4

Ecosystem specific

{
    "section": "core"
}