Skip to main content
Vulnerability Intelligence
Platform
Solutions
Customers
Resources
Company
Login
Get Demo
Vulnerability Intelligence
SUSE-SU-2020:1714-1
SUSE-SU-2020:1714-1
UNKNOWN
Security update for php5
Published Jun 23, 2020
Modified 5 years ago
Fix available
Details
This update for php5 fixes the following issues:
CVE-2020-7064: Fixed a one byte read of uninitialized memory in exif_read_data() (bsc#1168326).
CVE-2020-7066: Fixed URL truncation get_headers() if the URL contains zero (\0) character (bsc#1168352).
CVE-2019-11048: Improved the handling of overly long filenames or field names in HTTP file uploads (bsc#1171999).
Affected Packages
(54 packages)
apache2-mod_php5
SUSE Linux Enterprise Module for Web and Scripting 12
Fixed in:
5.5.14-109.76.1
php5
SUSE Linux Enterprise Module for Web and Scripting 12
SUSE Linux Enterprise Software Development Kit 12 SP4
Fixed in:
5.5.14-109.76.1
php5-bcmath
SUSE Linux Enterprise Module for Web and Scripting 12
Fixed in:
5.5.14-109.76.1
php5-bz2
SUSE Linux Enterprise Module for Web and Scripting 12
Fixed in:
5.5.14-109.76.1
php5-calendar
SUSE Linux Enterprise Module for Web and Scripting 12
Fixed in:
5.5.14-109.76.1
php5-ctype
SUSE Linux Enterprise Module for Web and Scripting 12
Fixed in:
5.5.14-109.76.1
php5-curl
SUSE Linux Enterprise Module for Web and Scripting 12
Fixed in:
5.5.14-109.76.1
php5-dba
SUSE Linux Enterprise Module for Web and Scripting 12
Fixed in:
5.5.14-109.76.1
php5-dom
SUSE Linux Enterprise Module for Web and Scripting 12
Fixed in:
5.5.14-109.76.1
php5-enchant
SUSE Linux Enterprise Module for Web and Scripting 12
Fixed in:
5.5.14-109.76.1
Show 44 more packages
References
REPORT
https://bugzilla.suse.com/1168326
REPORT
https://bugzilla.suse.com/1168352
REPORT
https://bugzilla.suse.com/1171999
WEB
https://www.suse.com/security/cve/CVE-2019-11048
WEB
https://www.suse.com/security/cve/CVE-2020-7064
WEB
https://www.suse.com/security/cve/CVE-2020-7066
ADVISORY
https://www.suse.com/support/update/announcement/2020/suse-su-20201714-1/
Upstream
CVE-2019-11048
CVE-2020-7064
CVE-2020-7066
Related
CVE-2019-11048
CVE-2020-7064
CVE-2020-7066
Ecosystems
SUSE Linux Enterprise Module for Web and Scripting 12
SUSE Linux Enterprise Software Development Kit 12 SP4
Timeline
Published
Jun 23, 2020
Modified
Jun 23, 2020
SUSE-SU-2020:1714-1 | Mondoo Vulnerability Intelligence