MGASA-2016-0267

Source
https://advisories.mageia.org/MGASA-2016-0267.html
Import Source
https://advisories.mageia.org/MGASA-2016-0267.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0267
Related
Published
2016-07-26T21:59:16Z
Modified
2016-07-26T21:51:35Z
Summary
Updated php/xmlrpc-epi/timezone packages fix security vulnerability
Details

Stack-based buffer overflow vulnerability in virtualfileex() (CVE-2016-6289).

Use After Free in unserialize() with Unexpected Session Deserialization (CVE-2016-6290).

Out of bound read in exifprocessIFDinMAKERNOTE() (CVE-2016-6291).

NULL Pointer Dereference in exifprocessuser_comment() (CVE-2016-6292).

localeacceptfrom_http() out-of-bounds access (CVE-2016-6294).

Use After Free Vulnerability in SNMP with GC and unserialize() (CVE-2016-6295).

heap-buffer-overflow (write) simplestring_addn() simplestring.c in php-xmlrpc (CVE-2016-6296).

Stack-based buffer overflow vulnerability in phpstreamzip_opener() (CVE-2016-6297).

The php package has been updated to version 5.6.24, fixing these issues and several other bugs. See the upstream ChangeLog for details.

The CVE-2016-6296 issue was in the xmlrpc-epi library, which has been patched.

Additionally, the timezone and php-timezonedb packages have been updated with the latest timezone data.

References
Credits

Affected packages

Mageia:5 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.6.24-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / xmlrpc-epi

Package

Name
xmlrpc-epi
Purl
pkg:rpm/mageia/xmlrpc-epi?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.54.2-5.1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / timezone

Package

Name
timezone
Purl
pkg:rpm/mageia/timezone?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2016f-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / php-timezonedb

Package

Name
php-timezonedb
Purl
pkg:rpm/mageia/php-timezonedb?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2016.6-1.mga5

Ecosystem specific

{
    "section": "core"
}